PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92775 requarks CVE debrief

CVE-2026-92775 is a high-severity server-side request forgery vulnerability in Wiki.js through 2.5.314. The vulnerability allows attackers with page editing permissions to inject img elements with the prefetch-candidate class, making the server request internal services and cloud metadata endpoints, with responses returned to the attacker. Wiki.js administrators and defenders should assess exposure and prioritize patching affected systems. The CVE record and NVD entry provide details on the vulnerability, but verification from official sources is required for affected versions and remediation steps.

Vendor
requarks
Product
Wiki.js
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-21
Advisory published
2026-09-16
Advisory updated
2026-09-21

Who should care

Wiki.js administrators, defenders, and security teams should assess exposure and prioritize patching affected systems. They should also review and update incident response plans, monitor server requests for suspicious activity, and restrict page editing permissions to trusted users. Additionally, they should verify affected versions and remediation steps from official sources and consider compensating controls for exposed systems.

Why it matters

CVE-2026-92775 is a high-severity server-side request forgery vulnerability in Wiki.js that allows attackers to make arbitrary requests to internal services and cloud metadata endpoints. Defenders should prioritize verifying and patching affected systems, restricting page editing permissions, and monitoring server requests for suspicious activity.

  • Potential unauthorized access to internal services
  • Possible exposure of cloud metadata
  • Required verification of affected versions and remediation steps
  • Need for monitoring server requests for suspicious activity

Technical summary

CVE-2026-92775 is a server-side request forgery vulnerability in the Image Prefetch renderer of Wiki.js through 2.5.314. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Defenders should prioritize verifying and patching affected systems, restricting page editing permissions, and monitoring server requests for suspicious activity.

Defensive priority

Wiki.js administrators and defenders should prioritize verifying and patching affected systems

Recommended defensive actions

  • Verify and apply patches for Wiki.js 2.5.314
  • Restrict page editing permissions to trusted users
  • Monitor server requests for suspicious activity
  • Review and update incident response plans
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the server-side request forgery vulnerability in Wiki.js through 2.5.314. However, the exact affected versions and remediation steps require verification from the official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92775 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92775

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92775 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92775

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.