Insufficient Session Expiration in YesWiki by YesWiki
CVE-2026-104468

6.3MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104468?

YesWiki versions prior to 4.6.7 are susceptible to an insufficient session expiration vulnerability, which permits attackers to reuse old password reset links. The absence of expiry timestamps on tokens allows unauthorized individuals, with access to unused reset URLs found in mailboxes, logs, backups, or browser history, to submit a new password via the checkEmailKey() function, potentially leading to unauthorized account access.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.