CVE-2026-37106 is a critical vulnerability in DokuWiki 2025-05-14b 'Librarian' 56.2. An issue in the register function in inc/auth.php allows remote attackers to create accounts. The supplier disputes this as intentional behavior when self-registration is configured, a non-default feature. This vulnerability has a CVSS score of 9.8, indicating critical severity. Administrators and users of DokuWiki 2025-0 [truncated]
CVE-2026-26477 is a denial of service vulnerability in Dokuwiki v.2025-05-14b 'Librarian' [56.2]. The issue is caused by the media_upload_xhr() function in the media.php file. A remote attacker can exploit this vulnerability to cause a denial of service. The vulnerability affects Dokuwiki users, and its impact is limited to denial of service attacks. The CVSS score is 4.3, and the CVSS severity is MEDIUM.