CVE-2026-92774: Incorrect Authorization in requarks Wiki.js
Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag information without proper authorization.
AI Analysis
Technical Summary
CVE-2026-92774 describes an incorrect authorization vulnerability in Wiki.js through version 2.5.314. The issue arises because page tags are omitted from authorization checks in multiple GraphQL resolvers, including list, tree, tags, searchTags, and links. As a result, attackers can query these resolvers to access restricted page metadata that should be protected by tag-based access restrictions. This flaw allows unauthorized information disclosure of page metadata without requiring elevated privileges or user interaction.
Potential Impact
The vulnerability enables unauthorized users with limited privileges to bypass tag-based access controls and retrieve restricted page metadata such as titles, descriptions, paths, and tag information. This leads to information disclosure but does not directly allow modification or deletion of content. The CVSS 4.0 base score is 5.3, indicating a medium severity impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to GraphQL endpoints and monitor for suspicious queries that may attempt to exploit this authorization bypass. Avoid exposing sensitive metadata through these resolvers where possible.
CVE-2026-92774: Incorrect Authorization in requarks Wiki.js
Description
Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag information without proper authorization.
CVSS v4.0
Score 5.3medium
Affected software
requarks
Wiki.js
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92774 describes an incorrect authorization vulnerability in Wiki.js through version 2.5.314. The issue arises because page tags are omitted from authorization checks in multiple GraphQL resolvers, including list, tree, tags, searchTags, and links. As a result, attackers can query these resolvers to access restricted page metadata that should be protected by tag-based access restrictions. This flaw allows unauthorized information disclosure of page metadata without requiring elevated privileges or user interaction.
Potential Impact
The vulnerability enables unauthorized users with limited privileges to bypass tag-based access controls and retrieve restricted page metadata such as titles, descriptions, paths, and tag information. This leads to information disclosure but does not directly allow modification or deletion of content. The CVSS 4.0 base score is 5.3, indicating a medium severity impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to GraphQL endpoints and monitor for suspicious queries that may attempt to exploit this authorization bypass. Avoid exposing sensitive metadata through these resolvers where possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-16T19:15:39.714Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aab005f55bf5e2cf5231df9
Added to database: 09/16/2026, 20:47:27 UTC
Last enriched: 09/16/2026, 22:01:51 UTC
Last updated: 09/16/2026, 23:41:34 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.