Sceawere

Vulnerability Detail

CVE-2026-104438UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T12:17:14.503Z",
  "pubdate": "2026-10-02T12:17:14.503Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a missing authorization vulnerability within the tags tool, specifically involving the listpagestag and includepages actions. The vulnerability resides in the application's failure to enforce Access Control List (ACL) constraints during the page enumeration process. This flaw allows both unauthenticated and unprivileged remote attackers to bypass security restrictions and gain unauthorized visibility into the platform's content structure. By supplying specific tag or page parameters to these actions, an attacker can enumerate the existence of restricted pages and retrieve body-derived titles that are intended to be protected by standard read-ACL permissions. The impact of this information disclosure includes the potential leakage of sensitive project hierarchies, internal document naming conventions, and restricted metadata. This vulnerability poses a significant risk to organizational confidentiality and information security, as it grants unauthorized users insight into sensitive or private data that should remain sequestered from public or low-privileged view.",
  "technicalDetails": "The vulnerability is identified as a broken access control issue rooted in the logic of the YesWiki tags tool. Specifically, the actions listpagestag and includepages fail to implement sufficient server-side validation against the configured read-ACLs when processing requests to enumerate pages. In a secure architecture, the application logic should verify the current user's session and associated permissions against the target page's access policy before returning data. In the affected versions of YesWiki, these specific actions perform the enumeration and subsequent retrieval of page titles without verifying if the requesting user possesses the requisite read privileges.\nThe exploitation flow begins when an attacker interacts with the vulnerable URI endpoints associated with the tags tool. An unauthenticated attacker can craft a HTTP request—either GET or POST—targeting the listpagestag or includepages action. By injecting a chosen tag parameter or a specific page name into the request, the attacker triggers the backend logic to query the page database. Because the underlying code lacks a conditional check to filter the result set based on the active ACL definitions, the engine proceeds to construct a response containing the titles of pages associated with that tag or page. This includes titles derived from the body content of pages that are otherwise restricted from the public or unauthorized users.\nThe technical root cause is an insecure functional implementation where the privilege boundary is ignored by the component responsible for generating page lists and inclusions. The vulnerability is present in versions of YesWiki prior to 4.6.7. Because the exploit does not require authentication or elevated privileges, the attack surface is exposed to any user capable of reaching the web application over the network. The information disclosed—primarily page names and derived titles—can be further leveraged to perform reconnaissance, map out private content structures, and potentially facilitate further targeted attacks by identifying the location of sensitive internal documentation. The breach of confidentiality is complete, as the application effectively broadcasts private data to any requestor, irrespective of their authorization state, thereby violating the principle of least privilege required for robust access control."
}
CVE-2026-104438: YesWiki Improper Authorization Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere