PT-2026-40432 · Wiki.Js · Wiki.Js
Tuannq2299
·
Published
2026-05-12
·
Updated
2026-05-12
·
CVE-2026-44224
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wiki.js versions prior to 2.5.313
Description
The
users.update GraphQL mutation allows the application of an arbitrary groups array directly to the database without validating the supplied group IDs. The resolver passes arguments to the model without ownership checks or restrictions on group assignments. A user with manage:users permissions, typically assigned to moderators, can assign themselves to the Administrators group by setting groups:[1]. Upon re-authentication, the resulting JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—carries manage:system permissions, granting full site administrator access.Recommendations
Update to version 2.5.313.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wiki.Js