PT-2026-104277 · Yeswiki · Yeswiki

·

CVE-2026-104467

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.6.7
Description An authorization bypass exists in the isAuthorized() function of the ApiService when public API mode is enabled. This allows unauthenticated attackers to access administrative API routes. Specifically, attackers can interact with the 'api/ci/update config' and 'api/archives' endpoints to overwrite system configurations or list, download, and delete backup archives.
Recommendations Update YesWiki to version 4.6.7 or later. As a temporary mitigation, disable the public API mode to prevent unauthorized access to the isAuthorized() function.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104467

Affected Products

Yeswiki