CVE-2026-92776: Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass

Published Sep 16, 2026
·
Updated

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.

Affected Software

1 affected component
Wiki.js Wiki.js<=2.5.314

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Wiki.js to a version that resolves this vulnerability.

    Fixed in 2.5.314

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user who has been granted access to a folder through a START or END page rule can exploit it when unrelated page paths share the allowed folder's literal prefix. The attacker does not need user interaction.

2

What access can an attacker gain?

The affected authorization matching can grant read and write access to unrelated pages whose paths begin or end with the same literal prefix as an authorized folder. This can bypass intended page-level access controls.

3

Are deployments affected by default?

The provided information identifies the issue in Wiki.js through 2.5.314, but does not state whether START or END page rules are enabled or present in the default configuration.

4

How can I identify potentially affected authorization rules?

Review START and END page rules that grant users access to folders, then identify unrelated page paths that share the same literal prefix without being within the intended path segment. Users assigned to those rules may have unintended read and write access to such pages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203