PT-2026-40432 · Wiki.Js · Wiki.Js

·

CVE-2026-44224

·

Published

2025-06-11

·

Updated

2026-05-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wiki.js versions prior to 2.5.313
Description The users.update GraphQL mutation allows the application of an arbitrary groups array directly to the database without validating the supplied group IDs. The resolver passes arguments to the model without ownership checks or restrictions on group assignments. A user with manage:users permissions, typically assigned to moderators, can assign themselves to the Administrators group by setting groups:[1]. Upon re-authentication, the resulting JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—carries manage:system permissions, granting full site administrator access.
Recommendations Update to version 2.5.313.

Exploit

Fix

Improper Privilege Management

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11230
CVE-2026-44224
GHSA-CQ3G-MWRG-V2RV

Affected Products

Wiki.Js