Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-37106

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.

A flaw was found in DokuWiki. A remote attacker can create an account through the registration function. This occurs when the DokuWiki instance is configured to allow self-registration, which is not the default setting. This could lead to the creation of unauthorized user accounts.

Отчет

This flaw in DokuWiki is rated as Low impact because it only affects instances configured for self-registration, which is not the default setting in Red Hat deployments. An attacker could create unauthorized user accounts if this non-default feature is enabled.

Меры по смягчению последствий

To mitigate this issue, ensure that the self-registration feature in DokuWiki is disabled if not explicitly required. This can typically be controlled within the DokuWiki configuration settings. Consult the DokuWiki documentation for specific instructions on managing user registration settings. If the DokuWiki service is reloaded or restarted after configuration changes, verify the setting has taken effect.

Дополнительная информация

Статус:

Low
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2495995DokuWiki: DokuWiki: Unauthorized account creation via registration function

EPSS

Процентиль: 41%
0.0051
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 месяца назад

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.

CVSS3: 9.8
nvd
около 1 месяца назад

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.

CVSS3: 9.8
debian
около 1 месяца назад

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote atta ...

CVSS3: 9.8
github
около 1 месяца назад

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to execute arbitrary code via the register function in inc/auth.php

EPSS

Процентиль: 41%
0.0051
Низкий

3.7 Low

CVSS3