Sceawere

Vulnerability Detail

CVE-2026-104456UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Second-Order SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a double-quote payload, then load non-admin ACL-filtered listings to read database contents and bypass read ACLs.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-10-02T12:17:17.490Z",
  "pubdate": "2026-10-02T12:17:17.490Z",
  "executiveSummary": "A critical second-order SQL injection vulnerability exists in YesWiki prior to version 4.6.7 within the AclService::updateRequestWithACL method.\nThe vulnerability arises from improper handling of stored user data, allowing an attacker to inject malicious SQL syntax into the database via a username.\nBy registering an account with a payload containing double-quotes, an attacker can manipulate the construction of database queries executed during the application's access control logic.\nThis flaw allows unauthorized users to bypass read ACL restrictions, potentially leading to the exposure of sensitive database contents.\nExploitation requires the attacker to possess the ability to self-register an account, which is then used to trigger the injection when the application performs ACL-filtered listing operations.\nThe risk is significant as it provides a mechanism for unauthorized data exfiltration, compromising the integrity of the application's access control enforcement mechanism.",
  "technicalDetails": "The vulnerability is located in the AclService::updateRequestWithACL function, specifically where stored username strings are concatenated directly into a SQL LIKE clause without undergoing adequate sanitization or parameterization.\nThis is a classic second-order SQL injection where the malicious input is first persisted into the database during the user registration process. The payload remains dormant until the application retrieves this username to evaluate ACLs for listing pages.\nThe attack flow commences with the attacker registering a new account. During the registration process, the attacker provides a crafted username containing double-quote characters ('\"') and SQL-specific syntax intended to break out of the string literal within the LIKE clause.\nOnce the malicious username is stored, the attacker navigates to an application feature that invokes AclService::updateRequestWithACL. Within this method, the system fetches the attacker's username to perform an access control check.\nBecause the username is concatenated into the query as an unescaped string, the injected quotes terminate the original SQL string literal. This allows the attacker to append additional SQL commands or modify the logic of the WHERE clause.\nBy successfully manipulating the query, the attacker can force the application to return database records that should have been restricted by the intended ACL policy.\nThe vulnerability affects all YesWiki versions prior to 4.6.7. It is classified as an authenticated vulnerability, although the authentication requirement is minimal as it only necessitates the ability to create a self-registered account.\nThe impact includes unauthorized information disclosure, as the attacker can leverage the injection to bypass read ACLs and extract data from the database that is not publicly visible. The exploitation is facilitated by the way YesWiki dynamically constructs database queries during the authorization process, creating a blind spot in the application's security model."
}
CVE-2026-104456: YesWiki Second-Order SQL Injection (HIGH Severity, CVSS: 7.6) | Sceawere