PatchSiren cyber security CVE debrief
CVE-2026-92775 requarks CVE debrief
CVE-2026-92775 is a high-severity server-side request forgery vulnerability in Wiki.js through 2.5.314. The vulnerability allows attackers with page editing permissions to inject img elements with the prefetch-candidate class, making the server request internal services and cloud metadata endpoints, with responses returned to the attacker. Wiki.js administrators and defenders should assess exposure and prioritize patching affected systems. The CVE record and NVD entry provide details on the vulnerability, but verification from official sources is required for affected versions and remediation steps.
- Vendor
- requarks
- Product
- Wiki.js
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-21
Who should care
Wiki.js administrators, defenders, and security teams should assess exposure and prioritize patching affected systems. They should also review and update incident response plans, monitor server requests for suspicious activity, and restrict page editing permissions to trusted users. Additionally, they should verify affected versions and remediation steps from official sources and consider compensating controls for exposed systems.
Why it matters
CVE-2026-92775 is a high-severity server-side request forgery vulnerability in Wiki.js that allows attackers to make arbitrary requests to internal services and cloud metadata endpoints. Defenders should prioritize verifying and patching affected systems, restricting page editing permissions, and monitoring server requests for suspicious activity.
- Potential unauthorized access to internal services
- Possible exposure of cloud metadata
- Required verification of affected versions and remediation steps
- Need for monitoring server requests for suspicious activity
Technical summary
CVE-2026-92775 is a server-side request forgery vulnerability in the Image Prefetch renderer of Wiki.js through 2.5.314. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Defenders should prioritize verifying and patching affected systems, restricting page editing permissions, and monitoring server requests for suspicious activity.
Defensive priority
Wiki.js administrators and defenders should prioritize verifying and patching affected systems
Recommended defensive actions
- Verify and apply patches for Wiki.js 2.5.314
- Restrict page editing permissions to trusted users
- Monitor server requests for suspicious activity
- Review and update incident response plans
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the server-side request forgery vulnerability in Wiki.js through 2.5.314. However, the exact affected versions and remediation steps require verification from the official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92775 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92775
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92775 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92775
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/geo-chen/oss/blob/main/wiki.md
-
Source reference
Unverified legacy reference
URL: https://github.com/requarks/wiki
-
Source reference
Unverified legacy reference
URL: https://github.com/requarks/wiki/blob/v2.5.314/server/modules/rendering/html-image-prefetch/renderer.js
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/wiki-js-through-2.5.314-server-side-request-forgery-via-image-prefetch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.