Authorization bypass through user-controlled key in Wiki.js - #VU151564
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to take over administrative accounts and cause an administrative lockout.
The vulnerability exists due to improper access control in the Wiki.js GraphQL user-management resolvers when handling mutations with arbitrary target user IDs. A remote user can modify passwords, disable TFA, or remove group memberships of more-privileged accounts to take over administrative accounts and cause an administrative lockout.
Exploitation requires an account with the manage:users permission.