Sceawere

Vulnerability Detail

CVE-2026-104443UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Semantic Triple Deletion Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-02T12:17:15.323Z",
  "pubdate": "2026-10-02T12:17:15.323Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an improper input validation vulnerability within the semantic triples deletion API. This security flaw originates from an empty-filter scope bypass, which fails to enforce access control boundaries during the triple removal process.\nThe vulnerability allows any authenticated user to manipulate semantic data without regard to ownership or authorization constraints. By supplying a specially crafted empty filter, an attacker can bypass intended security checks to delete arbitrary triples from the application’s semantic store.\nThe most critical impact of this vulnerability is the potential for a site-wide authorization lockout. An attacker can specifically target and delete the triple governing the 'admins-group' membership. By effectively stripping all users of administrative privileges, the attacker renders the site unmanageable and inaccessible to legitimate administrators.\nThis represents a high-risk security defect, as it requires only standard authenticated access to execute. The exploit does not require elevated privileges or specific administrative knowledge, making it accessible to any registered user within the environment. Organizations utilizing affected versions are at significant risk of unauthorized data modification and service denial.",
  "technicalDetails": "The vulnerability resides within the triples delete API component of YesWiki, which is responsible for managing semantic data operations. The root cause of the issue is insufficient server-side validation of the filter parameter supplied during deletion requests.\nIn a secure implementation, the API should mandate that a filter scope is provided and validated against the session's authenticated user identity to ensure that only authorized data is modified. However, the affected versions of YesWiki fail to enforce this restriction when the filter parameter is empty or improperly formatted.\nThe attack flow proceeds as follows: First, the attacker establishes an authenticated session within the YesWiki instance. Second, the attacker constructs an HTTP request targeting the triples delete endpoint. Third, the attacker intentionally submits an empty filter scope within the request payload. The backend logic, failing to validate the presence or ownership boundaries associated with the filter, proceeds to process the deletion command against the broader semantic data set rather than restricting it to user-owned triples.\nThis lack of scope enforcement grants the attacker unrestricted CRUD (Create, Read, Update, Delete) capabilities over the underlying semantic database. The most impactful payload behavior involves the targeting of membership triples. By identifying the subject, predicate, and object (SPO) tuple that defines the membership of the 'admins-group', the attacker can issue a deletion request that removes the mapping between administrative accounts and the group.\nThe consequence of this action is a total loss of administrative oversight. Because the system relies on these semantic triples to evaluate authorization decisions, the sudden deletion of group membership data results in a site-wide denial of access for administrative users. This effectively 'locks out' the site's owner, as there are no remaining entities with the privileges required to restore the missing triples or manage the system configuration.\nBecause the vulnerability exists in the API handling logic, it remains exploitable across any network segment where the web interface is reachable by an authenticated user. The vulnerability affects all YesWiki versions prior to 4.6.7, where the input sanitization logic for the deletion API was either absent or insufficiently robust to prevent scope escalation."
}
CVE-2026-104443: YesWiki Semantic Triple Deletion Bypass (HIGH Severity, CVSS: 8.1) | Sceawere