Access Control Bypass Vulnerability in YesWiki by YesWiki Team
CVE-2026-104455

6.9MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104455?

YesWiki prior to version 4.6.7 contains a vulnerability that allows unauthenticated attackers to bypass access controls. This flaw enables attackers to access restricted page content through the recentchangesrssplus RSS action, where they can retrieve 500-character excerpts of the latest pages, including drafts and notes meant to be read-restricted. This exposure of sensitive information poses significant security risks to users and their data.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.