CVE-2026-37106 Details
Description
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
A vulnerability allowing remote code execution has been identified in DokuWiki version 2025-05-14b 'Librarian' 56.2. The issue arises in the 'register' function within 'inc/auth.php', where the absence of proper security checks enables attackers to execute arbitrary code. Specifically, the vulnerability allows unauthorized users to create accounts without authentication, bypassing cross-site request forgery (CSRF) protections. The impact of this vulnerability varies based on the 'autopasswd' configuration: with 'autopasswd=1', attackers can create accounts that automatically generate passwords sent to the registered email, while 'autopasswd=0' allows immediate login with a submitted password, leading to account takeover.
To address this vulnerability, DokuWiki users should update to the latest version where this issue is fixed. Additionally, it's recommended to enable Access Control Lists and properly configure email services for password management.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | New CVE Received | [email protected] |