Description
YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

YesWiki versions earlier than 4.6.7 contain a missing authorization flaw in the listpagestag and includepages actions of the tags tool. The flaw allows unauthenticated or unprivileged users to embed these actions with a chosen tag or page name, causing the system to titles without applying the normal read‑ACL filters. The result is a disclosure of the names and titles of pages that are otherwise protected by access control, exposing sensitive page names and potential content identifiers.

Affected Systems

Any installation of YesWiki running a version prior to 4.6.7 is vulnerable. The affected components are the listpagestag and includepages actions within the tags tool. All users, including those with no prior authentication or with low privileges, can trigger the vulnerability by submitting content that includes the vulnerable tags.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, indicating high severity. No EPSS score is available, which offers no explicit exploitation probability, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is through normal HTTP requests to the site where an attacker can embed the vulnerable tags, potentially from any web browser or automated script. Because the flaw bypasses read‑ACL checks, a successful exploit can reveal internal page names and titles to anyone who can submit or view the affected content. The impact is a breach of confidentiality for protected page metadata, and the risk is elevated if sensitive information is inferred from page names or titles.

Generated by OpenCVE AI on October 2, 2026 at 12:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later, which fixes the missing authorization in the listpagestag and includepages actions.
  • If an upgrade is not immediately possible, disable the listpagestag and includepages actions within the tags tool, or block the entire tags tool for unauthenticated users to eliminate the attack surface.
  • Verify that all read‑ACL checks are enforced before rendering any page titles or names, and audit custom code or plugins that may bypass the standard visibility logic.

Generated by OpenCVE AI on October 2, 2026 at 12:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages.
Title YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-862
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T15:27:01.134Z

Reserved: 2026-10-02T00:50:26.604Z

Link: CVE-2026-104438

cve-icon Vulnrichment

Updated: 2026-10-02T15:25:51.649Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:14.503

Modified: 2026-10-02T16:16:46.120

Link: CVE-2026-104438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:05Z

Weaknesses