CVE-2026-104467
Deferred Deferred - Pending Action

Authorization Bypass in YesWiki

Vulnerability report for CVE-2026-104467, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has an authorization bypass vulnerability in the ApiService::isAuthorized() function. When public API mode is enabled, unauthenticated attackers can access admin-only API routes like api/ci/update_config and api/archives. This allows them to overwrite configurations and manage backup archives without proper authorization.

Detection Guidance

Check if public API mode is enabled in YesWiki by inspecting the configuration file for 'api_allowed_keys' => ['public' => true]. Test endpoints like api/ci/update_config and api/archives without authentication to see if they return sensitive data or allow modifications.

Impact Analysis

Attackers could exploit this to modify system configurations, list or download sensitive backup archives, or delete backups and custom presets. This could lead to data loss, unauthorized changes to the wiki, or exposure of confidential information.

Compliance Impact

This vulnerability could lead to unauthorized access or deletion of sensitive data, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations using affected YesWiki versions may face compliance violations and potential legal consequences.

Mitigation Strategies

Disable public API mode by setting 'api_allowed_keys' => ['public' => false] in the configuration. Block access to admin-only API routes at the web server or firewall level. Monitor logs for unauthorized access attempts to these endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104467. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart