Authorization Bypass in YesWiki Comments API Affects Multiple Versions
CVE-2026-104444
7.1HIGH
What is CVE-2026-104444?
YesWiki prior to version 4.6.7 is affected by an authorization bypass vulnerability within its comments API. This flaw allows authenticated users with low privileges to exploit the editComment route, enabling them to overwrite existing pages and comments. By crafting a specific POST request to the api/comments endpoint, attackers can target a victim's tag, effectively circumventing the per-page access control lists (ACLs) that are designed to protect the content. This vulnerability poses a significant risk to the integrity of user-generated content within the platform.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
