CVE-2026-104449
Deferred Deferred - Pending Action

YesWiki Page Overwrite via Bazar Entry Creation

Vulnerability report for CVE-2026-104449, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing page, overwriting its body for mass defacement and content destruction.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104449 is an access control flaw in YesWiki versions before 4.6.7. Unauthenticated attackers can overwrite any existing wiki page, including restricted pages like menus or homepages, by exploiting the Bazar entry-creation feature. The attack uses a crafted id_fiche parameter to match an existing page and bypass write ACL restrictions, enabling mass defacement or content destruction.

Detection Guidance

Check YesWiki versions for 4.6.6 or earlier using commands like 'composer show yeswiki/yeswiki' or inspecting the wiki's footer for version info. Monitor for unauthorized page modifications or defacement in the Bazar module by reviewing recent changes and access logs for suspicious entry submissions with attacker-controlled id_fiche parameters.

Impact Analysis

This vulnerability allows attackers to overwrite critical wiki pages, leading to mass defacement, content destruction, or unauthorized modifications. It bypasses authentication and authorization checks, meaning even protected pages can be altered without user interaction or privileges.

Compliance Impact

This vulnerability could lead to unauthorized modification or destruction of sensitive data stored in wiki pages, which may violate GDPR's integrity and availability principles if personal data is altered or deleted. For HIPAA, it risks unauthorized access and tampering with protected health information if such data is stored in affected wiki pages.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later immediately. Disable the Bazar module if unused. Enforce strict authentication for all page modifications and implement input validation to reject attacker-controlled id_fiche parameters. Review and tighten ACL settings to prevent unauthorized writes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104449. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart