Description
YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to retrieve 500-character body excerpts of every latest page, including read-restricted drafts and notes.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unrestricted Content Disclosure
Action: Apply Patch
AI Analysis

Impact

YesWiki versions before 4.6.7 contain an access control bypass that lets an unauthenticated attacker read restricted page content. By requesting the XML method of a page that hosts the recentchangesrssplus RSS action, the attacker receives 500‑character excerpts from every recently updated page, including drafts and notes that are normally read‑restricted. This vulnerability exposes confidential information that should be protected by the site’s access controls.

Affected Systems

The affected product is YesWiki from the YesWiki vendor. All installations running a version earlier than 4.6.7 are impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current widespread exploitation. The likely attack vector is a remote HTTP request to the recentchangesrssplus RSS endpoint, which is available to unauthenticated users. Once triggered, the attacker can extract snippets of any page that has been recently modified, potentially revealing sensitive draft content.

Generated by OpenCVE AI on October 2, 2026 at 12:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or later to remove the recentchangesrssplus RSS action bug.
  • If an upgrade is not immediately possible, disable the recentchangesrssplus plugin or block the RSS action endpoint from external access to prevent the XML method from being called.
  • Configure the server to restrict the XML method to authenticated users only, ensuring that only authorized personnel can request page excerpts via this endpoint.

Generated by OpenCVE AI on October 2, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to retrieve 500-character body excerpts of every latest page, including read-restricted drafts and notes.
Title YesWiki before 4.6.7 Read-ACL Bypass via recentchangesrssplus RSS Action
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-200
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T13:35:22.179Z

Reserved: 2026-10-02T00:53:58.504Z

Link: CVE-2026-104455

cve-icon Vulnrichment

Updated: 2026-10-02T13:35:17.816Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:17.323

Modified: 2026-10-02T14:17:08.610

Link: CVE-2026-104455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor