CVE-2026-37106: n/a
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
AI Analysis
Technical Summary
CVE-2026-37106 describes a scenario in DokuWiki 2025-05-14b "Librarian" 56.2 where remote attackers can create accounts through the register function in inc/auth.php. The supplier clarifies this is expected behavior when self-registration is enabled, which is not enabled by default and cannot be enabled without administrator awareness. No patch or remediation level is provided, and the vulnerability status is disputed. The CVSS 3.1 score is 9.8 (critical), reflecting the potential impact if self-registration is enabled.
Potential Impact
If self-registration is enabled in DokuWiki 2025-05-14b, remote attackers can create accounts without prior authorization, potentially leading to full confidentiality, integrity, and availability compromise as indicated by the CVSS score. However, since self-registration is a non-default feature and cannot be enabled without administrator knowledge, the risk is limited to environments where this feature is intentionally activated.
Mitigation Recommendations
Administrators should verify whether self-registration is enabled in their DokuWiki configuration. If not required, self-registration should remain disabled to prevent unauthorized account creation. Since this behavior is intentional and no official patch or remediation is provided, controlling configuration settings is the primary mitigation. Monitor vendor advisories for any future updates.
CVE-2026-37106: n/a
Description
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
CVSS v3.1
Score 9.8critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-37106 describes a scenario in DokuWiki 2025-05-14b "Librarian" 56.2 where remote attackers can create accounts through the register function in inc/auth.php. The supplier clarifies this is expected behavior when self-registration is enabled, which is not enabled by default and cannot be enabled without administrator awareness. No patch or remediation level is provided, and the vulnerability status is disputed. The CVSS 3.1 score is 9.8 (critical), reflecting the potential impact if self-registration is enabled.
Potential Impact
If self-registration is enabled in DokuWiki 2025-05-14b, remote attackers can create accounts without prior authorization, potentially leading to full confidentiality, integrity, and availability compromise as indicated by the CVSS score. However, since self-registration is a non-default feature and cannot be enabled without administrator knowledge, the risk is limited to environments where this feature is intentionally activated.
Mitigation Recommendations
Administrators should verify whether self-registration is enabled in their DokuWiki configuration. If not required, self-registration should remain disabled to prevent unauthorized account creation. Since this behavior is intentional and no official patch or remediation is provided, controlling configuration settings is the primary mitigation. Monitor vendor advisories for any future updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-04-06T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a443df227e9c79719767786
Added to database: 06/30/2026, 22:06:42 UTC
Last enriched: 07/23/2026, 22:23:36 UTC
Last updated: 08/13/2026, 12:41:09 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.