CVE-2026-104438
Deferred Deferred - Pending Action

Missing Authorization in YesWiki Pages Enumeration

Vulnerability report for CVE-2026-104438, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool. This allows unauthenticated or unprivileged attackers to enumerate pages without proper read-ACL filtering by embedding these actions with a chosen tag or page name. The vulnerability exposes the names and body-derived titles of pages that should be restricted by Access Control Lists (ACL).

Detection Guidance

To detect this vulnerability, check if your YesWiki instance is running a version before 4.6.7. You can use commands like 'curl -s http://your-wiki-url/ | grep -i yeswiki' to identify the version. Additionally, test if the listpagestag and includepages actions are accessible without authentication by appending '{{listpagestag tag=test}}' or '{{includepages page=test}}' to a wiki page and observing if restricted page names or titles are exposed.

Impact Analysis

An attacker could use this vulnerability to discover the names and titles of sensitive pages that are supposed to be restricted. This could help them plan further attacks by identifying targets or gathering sensitive metadata. While the default template does not leak full page content, the exposed metadata could still be valuable for targeted exploits.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive page metadata such as titles of ACL-restricted pages. Unauthorized disclosure of such information may violate data protection requirements under these regulations, particularly if the exposed data includes personally identifiable information or protected health information.

Mitigation Strategies

Immediately upgrade YesWiki to version 4.6.7 or later to address the missing authorization checks. If upgrading is not immediately possible, restrict access to the tags tool actions by modifying server configurations or using web application firewalls to block unauthorized requests to listpagestag and includepages endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104438. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart