CVE-2026-104443
Deferred Deferred - Pending Action

Empty Filter Scope Bypass in YesWiki Leading to Admin Group Deletion

Vulnerability report for CVE-2026-104443, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
yeswiki yeswiki to 4.6.6 (inc)
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has a vulnerability where an empty filter in the triples delete API bypasses scope checks. This allows any authenticated user to delete or forge semantic triples regardless of ownership. Attackers can remove the admin-group membership triple, emptying the admin group and causing a site-wide authorization lockout.

Detection Guidance

Check YesWiki versions before 4.6.7 by running: grep -r 'yeswiki' /path/to/yeswiki/version or check the admin panel. Monitor API logs for empty filter requests to /triples/delete endpoint. Look for unauthorized admin group modifications or triple deletions in the database.

Impact Analysis

An attacker could exploit this to delete critical admin-group membership triples, locking out all administrators and preventing site management. They could also forge or delete page-metadata triples and remove password-recovery keys, causing data loss or unauthorized access.

Compliance Impact

This vulnerability could lead to unauthorized data modification or deletion, violating integrity and availability requirements in GDPR and HIPAA. A site-wide admin lockout may also prevent access controls from functioning, potentially breaching compliance for data protection and security.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later immediately. If upgrading is not possible, restrict access to the triples delete API endpoint via firewall rules or web server configuration. Review and restore any deleted admin-group membership triples from backups.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104443. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart