PatchSiren

requarks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH requarks CVE published 2026-09-16

CVE-2026-92776

Wiki.js through 2.5.314 has a vulnerability where it fails to require path separators when matching START and END page rules. This allows attackers to access pages sharing a prefix with authorized folders. Users with access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls. Wiki.js administrators and users with folder access should assess their expo [truncated]