Missing Authorization Vulnerability in YesWiki Affects Unauthenticated Access
CVE-2026-104472
8.7HIGH
What is CVE-2026-104472?
YesWiki prior to version 4.6.7 is susceptible to a missing authorization vulnerability within its attachment download handler. This flaw allows unauthenticated attackers to circumvent access control lists (ACLs) for page reading. By utilizing specific known parameters—namely a page tag and file parameter—malicious actors can request the attachment download handler, resulting in unauthorized access to confidential documents from read-restricted pages. Organizations using affected versions are urged to implement the latest update to mitigate this security risk.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
