CRITICAL
DokuWiki
CVE published 2026-06-30
CVE-2026-37106
CVE-2026-37106 is a critical vulnerability in DokuWiki 2025-05-14b 'Librarian' 56.2. An issue in the register function in inc/auth.php allows remote attackers to create accounts. The supplier disputes this as intentional behavior when self-registration is configured, a non-default feature. This vulnerability has a CVSS score of 9.8, indicating critical severity. Administrators and users of DokuWiki 2025-0 [truncated]