Sceawere

Vulnerability Detail

CVE-2026-104444UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-02T12:17:15.490Z",
  "pubdate": "2026-10-02T12:17:15.490Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an authorization bypass vulnerability located within the comments API editComment functionality.\nThis vulnerability allows authenticated users with low-privilege status to perform unauthorized write operations, effectively overwriting arbitrary pages or comments within the system.\nThe flaw stems from improper access control enforcement on the 'pagetag' field, which enables attackers to circumvent per-page write Access Control Lists (ACLs).\nBy manipulating the request parameters, an attacker can designate a victim tag as the target, leading to unauthorized content replacement and the potential reparenting of existing site data.\nThe risk implication is significant as it facilitates unauthorized data modification, integrity compromise, and potential privilege escalation by altering sensitive page configurations.\nSuccessful exploitation requires authenticated access, though the attacker does not need high-level administrative privileges, significantly increasing the attack surface for collaborative environments.",
  "technicalDetails": "The vulnerability resides within the YesWiki comments API, specifically targeting the 'editComment' route associated with the 'api/comments' endpoint.\nThe root cause is an insecure implementation of authorization checks that fails to validate the ownership or modification rights of the 'pagetag' parameter provided by the client during an edit operation.\nUnder normal circumstances, YesWiki utilizes ACLs to restrict page modifications to authorized users. However, the API does not sufficiently bind the requested 'pagetag' to the authenticated user's permissions, allowing a request to reference a tag for which the user lacks write access.\nThe exploitation flow begins with the attacker crafting a POST request directed at the 'api/comments' endpoint. Within the request body, the attacker specifies a 'pagetag' field corresponding to a high-value or protected page owned by another user or the system.\nBy manipulating this field, the attacker bypasses server-side checks that are designed to enforce per-page write permissions. The backend processes the input and executes the update logic against the victim page instead of the user's own content.\nThis allows for the complete overwrite of existing content, which can be leveraged to inject malicious scripts, deface site resources, or modify structural elements by reparenting existing pages or comment threads.\nBecause the system trusts the 'pagetag' input provided in the POST request without verifying that the authenticated user maintains sufficient ACL privileges for that specific target, the application effectively delegates write authorization to the client.\nThis vulnerability is present in all versions prior to 4.6.7. Attackers can reach this endpoint via any standard network access as long as they possess a valid, low-privilege session, making it a persistent threat in environments that permit public or low-privileged account creation.\nPost-exploitation impact includes the loss of data integrity, unauthorized data exfiltration if the attacker reparents sensitive information, and potential cross-site scripting (XSS) if the system allows arbitrary content injection into pages that are later rendered for other users."
}
CVE-2026-104444: YesWiki Authorization Bypass Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere