CVE-2026-92776

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.

  • Published Sep 16, 2026
  • CVSS 8.6 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-92776 at the National Vulnerability Database