CVE-2026-92776: Requarks Wiki.js
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
Affected products
- Requarks Wiki.js: up to and including 2.5.314
Published 2026-09-16. Last modified 2026-09-24.