Description
YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing page, overwriting its body for mass defacement and content destruction.
Published: 2026-10-02
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Unauthenticated page overwrite leading to defacement and content loss
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in YesWiki versions prior to 4.6.7 allows an unauthenticated attacker to overwrite any existing wiki page, including those protected by write ACLs, by submitting a crafted entry through the Bazar module. The attacker controls the id_fiche field and can match it to an existing page slug, resulting in the page body being replaced with attacker-supplied content. This represents a critical integrity violation, as it enables mass defacement, unauthorized content injection, and permanent loss of legitimate wiki information. The weakness is a permission check failure (CWE‑639).

Affected Systems

YesWiki installations using the YesWiki application, specifically versions older than 4.6.7. Any deployment that has not yet applied the 4.6.7 update is vulnerable.

Risk and Exploitability

The CVSS score of 8.3 classifies the issue as High severity. EPSS information is not available, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote unauthenticated web request to the Bazar entry-creation endpoint, where the attacker can supply a crafted id_fiche parameter. Based on the description, it is inferred that an attacker simply needs network access to the web application to exploit this flaw.

Generated by OpenCVE AI on October 2, 2026 at 13:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later to eliminate the vulnerability.
  • If an immediate upgrade is not possible, disable the Bazar module or restrict its entry-creation functionality to authenticated users only.
  • Implement a server‑side validation or a firewall rule that rejects any Bazar request whose id_fiche matches an existing page slug, preventing unauthorized page overwrites.

Generated by OpenCVE AI on October 2, 2026 at 13:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing page, overwriting its body for mass defacement and content destruction.
Title YesWiki before 4.6.7 Unauthenticated Page Overwrite via Bazar id_fiche
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-639
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:21.736Z

Reserved: 2026-10-02T00:53:03.852Z

Link: CVE-2026-104449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:16.320

Modified: 2026-10-02T12:17:16.433

Link: CVE-2026-104449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:15:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key