<Vulnerability name="CVE-2026-37106">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-06-30T00:00:00</PublicDate>
    <Bugzilla id="2495995" url="https://bugzilla.redhat.com/show_bug.cgi?id=2495995" xml:lang="en:us">
DokuWiki: DokuWiki: Unauthorized account creation via registration function
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.7</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-306</CWE>
    <Details xml:lang="en:us" source="Mitre">
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in DokuWiki. A remote attacker can create an account through the registration function. This occurs when the DokuWiki instance is configured to allow self-registration, which is not the default setting. This could lead to the creation of unauthorized user accounts.
    </Details>
    <Statement xml:lang="en:us">
This flaw in DokuWiki is rated as Low impact because it only affects instances configured for self-registration, which is not the default setting in Red Hat deployments. An attacker could create unauthorized user accounts if this non-default feature is enabled.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this issue, ensure that the self-registration feature in DokuWiki is disabled if not explicitly required. This can typically be controlled within the DokuWiki configuration settings. Consult the DokuWiki documentation for specific instructions on managing user registration settings. If the DokuWiki service is reloaded or restarted after configuration changes, verify the setting has taken effect.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-37106
https://nvd.nist.gov/vuln/detail/CVE-2026-37106
https://gist.github.com/KyrieKlay/3260f4eeea025f2cd1daa7eb1360c5a1
https://github.com/dokuwiki/dokuwiki
https://github.com/dokuwiki/dokuwiki/issues/4682
    </References>
</Vulnerability>