← Terug naar overzicht

LeafWiki versions 0.1.0 through 0.10.0 contain a privilege escalation vulnerability in the user update API. An authenticated user can modify their own account role, escalating from a regular role such as 'viewer' to 'admin'. Exploitation only requires a valid authenticated account on the affected instance. Instances with restricted registration and only trusted users face lower practical risk. The vulnerability has been patched in version 0.10.1. As a mitigation, operators should restrict account creation and limit access to the user update API to trusted users or administrators only. The issue is tracked as CVE-2026-53527 and a security advisory has been published on GitHub.

Affected products

  • LeafWiki 0.1.0 through 0.10.0

Related CVE's

  • CVE-2026-53527

Categories

  • Identity & Access
  • Web Technologies