Vulnerability Description
LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`, to `admin`. Exploitation requires a valid authenticated LeafWiki user account. Instances without public registration and with only trusted users are at lower practical risk. Users should update to version 0.10.1 or greater. Until a patch is available, operators should restrict account creation and ensure that only trusted users have accounts on affected LeafWiki instances. If possible, access to the user update API should be restricted to trusted users or administrators only.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-53527?
CVE-2026-53527 is a vulnerability with a CVSS score of 8.8 (HIGH). LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate p...
How severe is CVE-2026-53527?
CVE-2026-53527 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53527?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.