LeafWiki versions 0.1.0 through 0.10.0 contain a privilege escalation vulnerability in the user update API. An authenticated user can modify their own account role, escalating from a regular role such as 'viewer' to 'admin'. Exploitation only requires a valid authenticated account on the affected instance. Instances with restricted registration and only trusted users face lower practical risk. The vulnerability has been patched in version 0.10.1. As a mitigation, operators should restrict account creation and limit access to the user update API to trusted users or administrators only. The issue is tracked as CVE-2026-53527 and a security advisory has been published on GitHub.