Sceawere

Vulnerability Detail

CVE-2026-104446UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body for spam and phishing.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-02T12:17:15.817Z",
  "pubdate": "2026-10-02T12:17:15.817Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an authentication bypass vulnerability within the contact mail AJAX handler.\nThis flaw allows unauthenticated remote attackers to leverage the wiki's internal SMTP configuration to dispatch arbitrary emails.\nThe vulnerability stems from improper access control validation within the mail handling module, enabling unauthorized actors to bypass security gates and interact directly with the mail dispatching service.\nThe impact is significant, as it facilitates the distribution of unsolicited bulk email (spam) or phishing campaigns, effectively turning the affected server into an open mail relay.\nThe risk implication involves potential reputation damage to the hosting infrastructure, blacklisting of the server's IP address by mail service providers, and the weaponization of the platform for malicious social engineering attacks.\nExploitation requires no prior authentication, necessitating that the attacker only possess network reachability to the target web application.\nDefensive measures require upgrading to version 4.6.7 or later, where security patches have been implemented to enforce proper session validation and authorization checks for the mail handler.",
  "technicalDetails": "The vulnerability resides in the contact mail AJAX handler, which acts as an interface between user-provided data and the server-side SMTP library. The root cause is a deficiency in input validation and access control mechanisms, specifically the lack of authentication enforcement when processing POST requests sent to the mail handler endpoint.\nIn a secure implementation, the AJAX handler should verify the session state or authorization tokens of the initiating user before permitting the instantiation of an email object. In affected YesWiki versions, the application fails to validate whether the requester possesses a valid session, allowing the handler to process requests even in an unauthenticated state.\nThe attack flow commences when an attacker identifies the relevant AJAX endpoint. By crafting an XMLHttpRequest (XHR) payload, the attacker sends a POST request to the handler. Because the application logic does not require mandatory 'field' or 'type' parameters, the attacker can manipulate the request body to inject custom headers and content.\nThe attacker submits arbitrary data for the SMTP envelope, including the recipient ('to'), sender ('from'), subject, and message body. The application, acting on behalf of the server's configured SMTP credentials, processes these inputs without sanitization or identity verification. Consequently, the wiki server initiates an SMTP transaction to the designated mail server and dispatches the attacker's message.\nThis vulnerability is classified as an authentication bypass that results in unauthorized message relaying. Since the email originates from the wiki server's internal SMTP settings, it may bypass some spam filters that trust mail originating from the server's IP address, increasing the likelihood of successful delivery for phishing content. The post-exploitation impact is limited to the server's capacity for sending mail; however, the unauthorized usage of the infrastructure constitutes a major security failure, leading to potential service disruption and the compromise of server reputation. The vulnerability exists until the specific handler is patched to require authentication or cryptographic tokens, such as CSRF protection or session-based verification, prior to executing the mail generation function."
}
CVE-2026-104446: YesWiki Authentication Bypass Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere