PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-37106 DokuWiki CVE debrief

CVE-2026-37106 is a critical vulnerability in DokuWiki 2025-05-14b 'Librarian' 56.2. An issue in the register function in inc/auth.php allows remote attackers to create accounts. The supplier disputes this as intentional behavior when self-registration is configured, a non-default feature. This vulnerability has a CVSS score of 9.8, indicating critical severity. Administrators and users of DokuWiki 2025-05-14b 'Librarian' 56.2 should be aware of this vulnerability, especially if self-registration is enabled.

Vendor
DokuWiki
Product
DokuWiki
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-07-21
Advisory published
2026-06-30
Advisory updated
2026-07-21

Who should care

Administrators and users of DokuWiki 2025-05-14b 'Librarian' 56.2 should be aware of this vulnerability, especially if self-registration is enabled. Security teams and vulnerability management teams should also be aware of this critical vulnerability and take necessary actions to mitigate the risk.

Technical summary

The vulnerability exists in the register function in inc/auth.php of DokuWiki 2025-05-14b 'Librarian' 56.2. This allows remote attackers to create accounts. The CVSS score is 9.8, indicating critical severity. The vulnerability is disputed by the supplier as it is an intended feature when self-registration is enabled. However, this does not negate the potential risk of unauthorized account creation.

Defensive priority

High priority due to critical CVSS score and potential for unauthorized account creation.

Recommended defensive actions

  • Review and verify self-registration settings in DokuWiki.
  • Monitor for unauthorized account creations.
  • Consider disabling self-registration if not required.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence is based on limited information from the CVE and NVD records. Further verification is needed to fully understand the vulnerability and its impact. The supplier disputes this as intentional behavior when self-registration is configured, a non-default feature. Administrators should verify their configuration and monitor for potential unauthorized account creations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T22:16:46.620Z and has not been modified since then.