Scope Bypass Vulnerability in YesWiki Product by YesWiki Vendor
CVE-2026-104443
7.2HIGH
What is CVE-2026-104443?
YesWiki versions prior to 4.6.7 are exposed to a scope bypass vulnerability in the triples delete API. This flaw allows any authenticated user to remove or forge arbitrary semantic triples, including the critical admins-group membership triple. By sending an empty filter to the triples delete endpoint, attackers can effectively empty the admin group, leading to a site-wide authorization lockout and potential loss of administrative access.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
