CVE-2026-37106: Critical severity DokuWiki Librarian vulnerability
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-37106?
CVE-2026-37106 has a critical severity score of 9.8 according to CVSS 3.1.
What issues does CVE-2026-37106 present?
CVE-2026-37106 allows a remote attacker to create an account via the register function in inc/auth.php.
Is self-registration a factor in CVE-2026-37106?
Yes, the behavior described in CVE-2026-37106 is intentional when DokuWiki is configured for self-registration, which is a non-default feature.
How can organizations mitigate the risks associated with CVE-2026-37106?
Organizations should review their DokuWiki configuration and consider disabling self-registration if it's not needed to mitigate risks associated with CVE-2026-37106.
When was CVE-2026-37106 published?
CVE-2026-37106 was published on June 30, 2026.