YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments. | |
| Title | YesWiki before 4.6.7 Authorization Bypass via Comments API editComment | |
| First Time appeared |
Yeswiki
Yeswiki yeswiki |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yeswiki
Yeswiki yeswiki |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T11:38:18.369Z
Reserved: 2026-10-02T00:53:03.851Z
Link: CVE-2026-104444
No data.
Status : Deferred
Published: 2026-10-02T12:17:15.490
Modified: 2026-10-02T12:17:15.607
Link: CVE-2026-104444
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:15:14Z
Weaknesses