Sceawere
Vulnerability Detail
CVE-2026-104449UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Unauthorized Page Overwrite Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing page, overwriting its body for mass defacement and content destruction.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-02T12:17:16.320Z",
"pubdate": "2026-10-02T12:17:16.320Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an access control vulnerability within the Bazar entry-creation mechanism. This flaw permits unauthenticated remote attackers to bypass established write Access Control Lists (ACLs) and overwrite existing wiki page content.\nThe vulnerability originates from insufficient server-side validation of the 'id_fiche' parameter during the entry submission process. By manipulating this identifier to match the unique ID of a targeted page, an attacker can force the application to treat the submission as an update to an existing resource rather than the creation of a new one.\nThe impact is significant, as it enables unauthorized modification or destruction of restricted wiki content, potentially facilitating mass defacement, information corruption, or the disruption of operational integrity. As the vulnerability requires no prior authentication, it is highly accessible to external threat actors. Mitigation requires upgrading to version 4.6.7 or later, where appropriate access controls and input validation have been implemented to prevent the collision of resource identifiers.\nThe risk is categorized as high, given the potential for unauthorized data manipulation within the wiki environment.",
"technicalDetails": "The vulnerability resides in the Bazar plugin's entry-creation workflow within YesWiki. The root cause is an insecure implementation of the object update logic, where the system fails to verify that the user submitting the entry possesses the required permissions to modify the resource associated with the provided 'id_fiche'.\nDuring the standard entry-creation flow, the application processes incoming POST requests intended to instantiate new wiki content. When the 'id_fiche' parameter is present in the request payload, the application's underlying logic incorrectly assumes that the operation is an update request for an existing resource if a match is found in the database. The system lacks a mandatory authorization check to ensure the requester is the authorized owner or holds sufficient administrative privileges to alter the target page.\nThe attack flow proceeds as follows: 1) The attacker identifies a target wiki page and extracts its identifier (id_fiche) via the application's public interface or metadata headers. 2) The attacker crafts a malicious HTTP POST request targeting the Bazar entry-creation endpoint. 3) The attacker populates the request body with the desired malicious content and inserts the target's 'id_fiche' into the request parameters. 4) Upon processing the request, the application fails to perform a secondary lookup of the ACL associated with the targeted 'id_fiche'. 5) The application overwrites the existing page's body content with the attacker-provided payload. 6) Because the application treats this as a valid submission, the change is committed to the backend store, resulting in immediate unauthorized modification.\nThis vulnerability is particularly critical because it bypasses existing ACLs designed to restrict modifications to sensitive documentation. The lack of validation on the 'id_fiche' parameter allows an attacker to perform unauthorized 'write' operations despite the targeted page being protected. The exploit is trivial to execute and does not require complex instrumentation beyond standard HTTP request manipulation. Post-exploitation impact includes persistent defacement of the platform and the potential for injecting malicious content to facilitate further attacks, such as cross-site scripting (XSS) or social engineering, depending on the sanitization policies of the wiki engine."
}