Description
YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body for spam and phishing.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unrestricted Email Sending (Open Mail Relay)
Action: Immediate Patch
AI Analysis

Impact

YesWiki before 4.6.7 has an authentication bypass in the contact mail AJAX handler that lets unauthenticated attackers send email through the wiki's SMTP server, allowing spam or phishing. The flaw is a CWE-306 Authentication Bypass, and it requires no parameters in the POST request. Attackers can supply arbitrary recipient, sender, subject, and body. The vulnerability permits the wiki to act as an open mail relay without access control, which can be abused to deliver large volumes of spam, phishing, or other malicious content. The impact is confined to the mail functionality of the affected instance, with a CVSS score of 6.9 reflecting moderate severity. The flaw is not listed in the CISA KEV catalog and EPSS data is not available, but the straightforward unauthenticated attack path makes it exploitable.

Affected Systems

All YesWiki installations running versions earlier than 4.6.7 are vulnerable, as documented by the YesWiki security advisory.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate risk, with no EPSS data and not listed in the KEV catalog. Attackers only need to send a POST request to the known AJAX endpoint without authentication, making exploitation trivial if the wiki is publicly accessible.

Generated by OpenCVE AI on October 2, 2026 at 12:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update YesWiki to version 4.6.7 or later to remove the authentication bypass.
  • If an update is not immediately possible, restrict access to the mail handler by blocking unauthenticated POST requests or disabling the mail functionality entirely.
  • Reconfigure the underlying SMTP server to require authentication or restrict relay access to known, trusted IP addresses so that the wiki cannot be used as an open relay.

Generated by OpenCVE AI on October 2, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body for spam and phishing.
Title YesWiki before 4.6.7 Unauthenticated Open Mail Relay via Contact Mail Handler
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-306
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:54:38.241Z

Reserved: 2026-10-02T00:53:03.852Z

Link: CVE-2026-104446

cve-icon Vulnrichment

Updated: 2026-10-02T14:54:10.364Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:15.817

Modified: 2026-10-02T15:17:07.013

Link: CVE-2026-104446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function