Description
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like bazar, breaking core site functionality.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service (critical functionality loss)
Action: Patch Immediately
AI Analysis

Impact

YesWiki versions before 4.6.7 contain a cross‑site request forgery vulnerability in the autoupdate UpdateAction module that allows an attacker to issue an unprotected GET request with action=delete and a package name. When a logged‑in administrator follows a crafted link, the specified package is deleted, which can remove essential extensions such as bazar and break core site functionality. This flaw is identified as CWE‑352 and results in a loss of service rather than direct code execution.

Affected Systems

The affected product is YesWiki, the popular open‑source wiki engine. All installations using YesWiki versions earlier than 4.6.7 are vulnerable; the specific versions prior to 4.6.7 have been listed as impacted. No further sub‑version details are provided in the advisory.

Risk and Exploitability

The CVSS score is 7.1, indicating a moderate to high severity exploiting this flaw. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated administrator to be tricked into visiting a crafted link, so exploitation relies on social engineering and the presence of an active admin session. Given the potential for widespread service disruption, the risk is considered significant for sites that rely on installed extensions.

Generated by OpenCVE AI on October 2, 2026 at 12:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later, which removes the vulnerable autoupdate UpdateAction code.
  • If an upgrade is not immediately possible, disable the autoupdate UpdateAction feature or restrict DeleteAction to trusted admin interfaces to prevent unauthorized GET requests.
  • Verify that all critical extensions are present after patching or re‑install any that were removed during an exploit attempt.

Generated by OpenCVE AI on October 2, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like bazar, breaking core site functionality.
Title YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-352
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T13:33:43.070Z

Reserved: 2026-10-02T00:53:03.852Z

Link: CVE-2026-104447

cve-icon Vulnrichment

Updated: 2026-10-02T13:33:38.950Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:15.990

Modified: 2026-10-02T14:17:08.343

Link: CVE-2026-104447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:45:19Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)