CVE-2026-92776
Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
- Published Sep 16, 2026
- CVSS 8.6 high
- 0.4% chance of exploitation in the next 30 days (EPSS)