Authorization Bypass in YesWiki Comments API Affects Multiple Versions
CVE-2026-104444

7.1HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104444?

YesWiki prior to version 4.6.7 is affected by an authorization bypass vulnerability within its comments API. This flaw allows authenticated users with low privileges to exploit the editComment route, enabling them to overwrite existing pages and comments. By crafting a specific POST request to the api/comments endpoint, attackers can target a victim's tag, effectively circumventing the per-page access control lists (ACLs) that are designed to protect the content. This vulnerability poses a significant risk to the integrity of user-generated content within the platform.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.