{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wiki.js--2.5.314/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wiki_js:wiki_js:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92776"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wiki.js (\u003c= 2.5.314)"],"_cs_severities":["high"],"_cs_tags":["access-control","web-application","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Wiki.js"],"content_html":"\u003cp\u003eWiki.js through version 2.5.314 contains an access control bypass vulnerability (CVE-2026-92776) resulting from a flaw in how the application validates START and END page rules. The application fails to strictly require path separators when enforcing these rules, which allows an attacker with legitimate access to a specific folder to inadvertently or maliciously access, read, and modify pages outside their authorized scope, provided those pages share a common name prefix with the authorized folder. This vulnerability can lead to unauthorized information disclosure and modification of wiki content by authenticated users who have been granted restricted access. This is a critical concern for environments relying on Wiki.js for sensitive documentation management where organizational boundaries are enforced through path-based permissions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to bypass intended access control lists (ACLs). An attacker could view sensitive documentation or modify pages they are not authorized to access. This primarily affects organizations using Wiki.js to host confidential or internal documentation where fine-grained folder-level permissions are required to segregate user access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Wiki.js to a version later than 2.5.314 to ensure proper path separator enforcement in ACL rules.\u003c/li\u003e\n\u003cli\u003eAudit existing page permissions and folder structures for overlapping naming conventions that may be susceptible to prefix-based bypasses.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous access patterns where users are accessing documentation paths outside of their assigned organizational units or roles.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T23:51:58Z","date_published":"2026-09-16T23:51:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wikijs-bypass/","summary":"Wiki.js versions 2.5.314 and earlier contain an access control vulnerability where insufficient path validation allows authenticated users to access unauthorized pages sharing a common prefix.","title":"Access Control Bypass in Wiki.js via Path Prefix Confusion","url":"https://feed.craftedsignal.io/briefs/2026-09-wikijs-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Wiki.js (\u003c= 2.5.314)","version":"https://jsonfeed.org/version/1.1"}