Description
YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Patch ASAP
AI Analysis

Impact

YesWiki versions prior to 4.6.7 contain an authorization bypass flaw in the comments API editComment route. An authenticated user with low privileges can supply a custom pagetag value when posting to the api/comments endpoint, causing the request to target the specified page instead of the intended comment. This allows the attacker to overwrite arbitrary pages or comments and to reparent existing pages or comments, effectively circumventing the normal per-page write access controls and compromising content integrity.

Affected Systems

The vulnerability affects YesWiki installations identified as "yeswiki:yeswiki" and applies to all releases before 4.6.7. No additional product or version details are provided beyond the base packaging prior to the 4.6.7 release.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity but not critical. EPSS is currently not available, so the current exploitation probability cannot be quantified. The issue is not listed in the CISA KEV catalog. The likely attack vector is the public Comments API; an attacker who is already authenticated can trigger the exploit by sending a POST request to /api/comments with a manipulated pagetag. The exploit requires user credentials but grants privileges that exceed the intended access level.

Generated by OpenCVE AI on October 2, 2026 at 12:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later.
  • Restrict write permissions for all low‑privilege users to prevent unauthorized page or comment modifications.
  • Monitor application logs for abnormal editComment API usage and investigate any unexpected modifications.

Generated by OpenCVE AI on October 2, 2026 at 12:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.
Title YesWiki before 4.6.7 Authorization Bypass via Comments API editComment
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-639
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:18.369Z

Reserved: 2026-10-02T00:53:03.851Z

Link: CVE-2026-104444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:15.490

Modified: 2026-10-02T12:17:15.607

Link: CVE-2026-104444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key