Access Control Vulnerability in YesWiki Versions Prior to 4.6.7
CVE-2026-104449

8.3HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104449?

YesWiki prior to version 4.6.7 is susceptible to an access control vulnerability that enables unauthorized users to overwrite existing wiki pages. This exploitation occurs through the Bazar entry-creation mechanism, where attackers can manipulate requests to overwrite page contents, regardless of write access control lists (ACLs) in place. This flaw can be leveraged for mass defacement and significant content destruction, posing a severe threat to the integrity of the content hosted on affected instances.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.