Access Control Bypass Vulnerability in YesWiki by YesWiki Team
CVE-2026-104455
6.9MEDIUM
What is CVE-2026-104455?
YesWiki prior to version 4.6.7 contains a vulnerability that allows unauthenticated attackers to bypass access controls. This flaw enables attackers to access restricted page content through the recentchangesrssplus RSS action, where they can retrieve 500-character excerpts of the latest pages, including drafts and notes meant to be read-restricted. This exposure of sensitive information poses significant security risks to users and their data.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
