A critical security flaw in DokuWiki, a popular open-source wiki platform, has been confirmed by developer Andreas Gohr. The vulnerability affects nearly all versions of DokuWiki released in the past decade and can be exploited with just write access to the wiki. The fix was released the same evening the issue was discovered, but it is only available in the latest version of the software. Additionally, the Debian Linux package, which many users rely on, does not yet include the patch. The fix also causes issues with certain plugins that rely on storing PHP objects in the cache. The vulnerability was first reported by a researcher named sebastianosrt, who sent an email detailing the flaw but received no response. After not hearing back, he opened a public ticket to alert the project’s maintainer. The email was marked as spam and was only retrieved by Gohr eight minutes after the ticket was created. Within an hour, Gohr classified the bug as critical, noting that it allows attackers to execute arbitrary code remotely or delete files from the server. While the flaw requires write access to exploit, it poses a serious risk for wikis that allow user contributions or open registration. In such cases, an attacker could start with something as simple as correcting a typo and escalate to full control of the server. Nearly all versions of DokuWiki from the last ten years are affected, meaning a large number of users are potentially at risk. The fix was included in version 2026-07-14c of DokuWiki. Users running older versions must update their software immediately, as previous major releases did not include the patch. The Debian Linux repositories have not yet adopted the fix, so users relying on those packages need to take additional steps. As a temporary workaround, Gohr recommends disabling the "usedraft" feature, which is enabled by default. The updated version prevents plugins from storing PHP objects in the instruction cache, which can cause errors in existing plugins. For example, the bureaucracy plugin’s forms may no longer work properly, and users may encounter errors on wiki pages. While the gallery plugin has been updated to accommodate this change, it is unclear how many other plugins will be affected. There is no official CVE identifier or public announcement, and all details are available in an open ticket on DokuWiki’s GitHub repository, where users can provide further input.