CVE-2026-104439
Deferred Deferred - Pending Action

YesWiki User Enumeration via LostPasswordAction

Vulnerability report for CVE-2026-104439, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-204 The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has a user enumeration vulnerability in LostPasswordAction.php. Unauthenticated attackers can submit email addresses to the password recovery page and receive different responses based on whether the email is registered. This allows attackers to confirm valid accounts for phishing or password-spraying attacks.

Detection Guidance

To detect this vulnerability, you can send HTTP POST requests to the password recovery endpoint with different email addresses and observe the responses. A valid account will return a success message while an invalid one will show an error. Example using curl: curl -X POST -d 'email=test@example.com' http://target.com/?wiki=LostPasswordAction. Compare responses for 'success' vs 'email not registered' messages.

Impact Analysis

Attackers can identify valid email accounts to target with phishing or password-spraying attacks. This could lead to unauthorized access to accounts if users reuse passwords or fall for phishing attempts. The lack of rate limiting enables large-scale probing of accounts.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by exposing user email addresses through user enumeration. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. Unauthorized disclosure of registered emails may violate these regulations if user accounts contain sensitive data.

Mitigation Strategies

Immediately upgrade YesWiki to version 4.6.7 or later. As a temporary measure, implement rate limiting on the password recovery endpoint and add CAPTCHA protection. Modify LostPasswordAction.php to return the same generic message for all requests regardless of account existence while still sending reset emails only to valid accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104439. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart