Description
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file
In plain language
AI Worth attentionA vulnerability in DokuWiki’s “Librarian” upload feature lets a remote attacker trigger denial-of-service with a crafted request; small businesses should review exposure and plan an upgrade, but there’s no known public fix yet.
In DokuWiki v.2025-05-14b “Librarian” [56.2], remote attackers can trigger a denial of service by sending a malicious request that abuses the media_upload_xhr() function in media.php; exploitation requires low effort and no user interaction.
What to do now
- Identify whether your DokuWiki is running version v.2025-05-14b “Librarian” [56.2].
- Check whether DokuWiki’s media upload/XHR upload feature is reachable from the internet in your setup (public access to the wiki and its upload endpoints).
- If you are affected, restrict access to the wiki from the internet (for example, allow only your office/VPN IPs or use a reverse proxy with tight access rules).
- Watch for an official DokuWiki update that addresses CVE-2026-26477 and upgrade immediately when a fixed version is published.
- Ensure you have protections in place to blunt malicious requests (rate limiting / request filtering at your web server or reverse proxy).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-26477 and every CVE in our database. Create a free account — no credit card required.
Create Free Account