CVE-2026-104446
Deferred Deferred - Pending Action

Authentication Bypass in YesWiki via AJAX Mail Handler

Vulnerability report for CVE-2026-104446, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body for spam and phishing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104446 is an authentication bypass in YesWiki versions before 4.6.7. It allows unauthenticated attackers to send emails through the wiki's SMTP server by exploiting a flaw in the contact mail AJAX handler. The vulnerability occurs because the system incorrectly initializes an access check variable to true, enabling attackers to bypass authentication by omitting certain parameters and supplying crafted input. This lets them control recipient, sender, subject, and body fields, turning the wiki into an open mail relay for spam or phishing.

Detection Guidance

To detect this vulnerability, monitor for unusual outbound SMTP traffic from your YesWiki server. Check for POST requests to /<AnyPage>/mail endpoints without proper authentication. Inspect logs for emails sent from the wiki's SMTP server with spoofed sender addresses or unexpected recipients.

Impact Analysis

This vulnerability allows attackers to send spam or phishing emails using your wiki's SMTP server. This can lead to your domain being blacklisted by email providers, reputational damage, and potential legal or compliance issues. Your server's resources may also be consumed by processing unauthorized email traffic.

Compliance Impact

This vulnerability could violate GDPR if personal data is exposed through unauthorized email transmission. For HIPAA, it may risk unauthorized disclosure of protected health information if emails contain such data. Organizations could face fines or penalties for failing to protect sensitive data due to this flaw.

Mitigation Strategies

Immediately upgrade YesWiki to version 4.6.7 or later. If upgrading is not possible, disable the contact mail AJAX handler by removing or restricting access to the mail.php file. Configure the wiki's contact_from setting to enforce sender validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104446. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart