CVE-2026-104469
Deferred Deferred - Pending Action

Session Fixation in YesWiki Prior to 4.6.7

Vulnerability report for CVE-2026-104469, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-384 Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

YesWiki before version 4.6.7 has a session fixation vulnerability where the PHP session ID is not regenerated during login. This allows attackers who obtain a victim's pre-authentication session cookie to reuse it after login, hijacking the authenticated session and accessing private content or performing actions with the victim's privileges.

Detection Guidance

To detect this vulnerability, check if your YesWiki instance is running a version before 4.6.7. Inspect the session handling in AuthController.php to confirm if session IDs are regenerated upon login. Monitor network traffic for session cookie reuse after authentication.

Impact Analysis

An attacker could gain unauthorized access to your YesWiki account, view or modify private content, perform administrative actions, or impersonate you. This requires the attacker to set or learn your pre-authentication session cookie, which may happen through shared devices or network attacks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using vulnerable YesWiki versions may face compliance breaches, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Immediately upgrade YesWiki to version 4.6.7 or later to patch the session fixation vulnerability. If upgrading is not possible, implement session_regenerate_id(true) in the login flow to regenerate session IDs after authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104469. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart