CVE-2026-104468
Deferred Deferred - Pending Action

Insufficient Session Expiration in YesWiki

Vulnerability report for CVE-2026-104468, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has a vulnerability where password reset tokens do not expire. Attackers can reuse old reset links to take over accounts if they obtain unused reset URLs from sources like mailboxes, logs, backups, or browser history.

Detection Guidance

Check YesWiki versions for 4.6.6 or earlier. Inspect password reset links in mailboxes, logs, backups, or browser history for unused tokens. Monitor for unauthorized password changes or account access.

Impact Analysis

If an attacker gains access to an old reset URL, they can submit a new password through the vulnerable function and take over your account. This could lead to unauthorized access to sensitive data or actions performed on your behalf.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements for safeguarding protected health information.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later. Invalidate all existing password reset tokens. Review and remove any stored reset URLs in logs or backups. Implement token expiry timestamps in future versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104468. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart