Description
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: User Enumeration
Action: Assess Impact
AI Analysis

Impact

YesWiki versions prior to 4.6.7 have a flaw in the LostPasswordAction.php script that exposes whether an email address is registered. By submitting any email address to the password‑recovery URL, attackers receive different responses, allowing them to enumerate valid user accounts without authentication. This discovery can facilitate targeted phishing or password‑spraying attacks against those accounts. The weakness is a denial of information confidentiality (CWE‑204).

Affected Systems

All deployments of YesWiki running any release before version 4.6.7 are affected. The enumerated vulnerability exists in the yeswiki product, as identified by the CPE cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*.*

Risk and Exploitability

The CVSS base score is 7.1, indicating a high severity, but the EPSS score is not available, and it is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability simply by sending unauthenticated HTTP requests to the lost‑password page, which lacks rate‑limiting or additional checks. Given the lack of defensive controls, the exploitation likelihood is fairly high for an attacker who knows or can guess a target domain. If the enumeration is confirmed, it may lead to credential‑guessing campaigns or phishing, affecting the confidentiality of user accounts and potentially causing broader compromise if credentials are reused.

Generated by OpenCVE AI on October 2, 2026 at 12:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest YesWiki release (4.6.7 or newer) which removes the enumeration logic from LostPasswordAction.php.
  • Configure web‑application or server‑level rate limiting on the password‑recovery endpoint to mitigate automated enumeration attempts.
  • If an upgrade is pending, temporarily disable or obscure the lost‑password recovery page. Alternatively, return a generic success message regardless of the email address supplied, preventing response discrimination.

Generated by OpenCVE AI on October 2, 2026 at 12:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.
Title YesWiki before 4.6.7 User Enumeration via Lost-Password Flow
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-204
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T13:31:48.944Z

Reserved: 2026-10-02T00:50:26.604Z

Link: CVE-2026-104439

cve-icon Vulnrichment

Updated: 2026-10-02T13:31:44.466Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:14.670

Modified: 2026-10-02T14:17:08.083

Link: CVE-2026-104439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:13Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy