Sceawere
Vulnerability Detail
CVE-2026-104455UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Access Control Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Exposure of Sensitive Information to an Unauthorized Actor
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to retrieve 500-character body excerpts of every latest page, including read-restricted drafts and notes.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T12:17:17.323Z",
"pubdate": "2026-10-02T12:17:17.323Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an access control bypass vulnerability, classified as an Improper Authorization flaw. This security deficit allows unauthenticated remote attackers to retrieve unauthorized content from restricted pages, including private drafts and internal notes.\nThe vulnerability resides within the 'recentchangesrssplus' RSS action component. By manipulating specific request parameters, an adversary can bypass standard authentication mechanisms to intercept sensitive information. The technical impact involves the exfiltration of the initial 500 characters of the body content for pages indexed within the recent changes feed. This exposure presents significant risk, as it allows for the leakage of confidential information that is intended to be protected by YesWiki's internal permission systems.\nNo authentication is required to initiate the attack, making this a low-complexity, high-impact exploit for remote actors. Remediation requires an immediate update to version 4.6.7 or later, where the authorization logic for RSS feeds has been hardened.",
"technicalDetails": "The vulnerability exists in the 'recentchangesrssplus' action, a functional component responsible for generating RSS feeds based on recent wiki modifications. The root cause of this vulnerability is an insufficient access control check within the implementation of this specific action. While the system is designed to verify user permissions before rendering page content, the 'recentchangesrssplus' module fails to adequately validate the session context or the authorization status of the requester when processing the 'xml' method request.\nThe exploitation process is straightforward: an unauthenticated attacker targets the YesWiki instance and constructs a crafted HTTP request pointing to the 'recentchangesrssplus' action. By specifically requesting the 'xml' output format, the attacker forces the application to generate an RSS feed containing the most recent site activities. Because the underlying code fails to enforce read-restriction policies, the response object includes metadata and body excerpts for pages that are otherwise marked as restricted, private, or drafts.\nWhen a request is submitted, the backend script retrieves the last several updates from the database. It then serializes this data into an XML structure. During the serialization process, the application logic populates the content field by extracting the first 500 characters of the wiki page body. Due to the lack of an authorization gate, the query does not filter out restricted or draft-status pages before concatenation. Consequently, the resultant XML output contains the plaintext content of these protected pages, which is then transmitted directly to the unauthenticated attacker.\nThis vulnerability is classified as an improper authorization issue rather than a standard injection flaw, as it leverages existing legitimate functionality to bypass security boundaries. The impact is significant as it provides a side-channel for data exfiltration, allowing an attacker to map restricted content, identify internal project notes, or gain unauthorized insights into private wiki documentation. The attack requires no special privileges, and since it functions via standard HTTP GET requests, it is highly observable in logs but difficult to prevent without an explicit application patch. The vulnerability remains present in all deployments of YesWiki prior to 4.6.7, where the developers introduced stricter validation checks on the page-reading function called by the RSS generation service."
}