Sceawere

Vulnerability Detail

CVE-2026-104468UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Insufficient Session Expiration

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.8
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Insufficient Session Expiration
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.8",
  "pubDate": "2026-10-02T12:17:19.540Z",
  "pubdate": "2026-10-02T12:17:19.540Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an insufficient session expiration vulnerability within the password reset mechanism. The flaw originates from the absence of temporal validation logic for password reset tokens. By failing to include expiry timestamps, the system treats generated reset links as perpetually valid until a successful password change occurs. This lack of state enforcement poses a critical risk to account security. An attacker who gains unauthorized access to a reset URL—whether through compromised mailboxes, server-side logs, system backups, or browser history—can leverage this persistent link to initiate an account takeover. The vulnerability does not require the attacker to have existing privileges, effectively lowering the barrier for account compromise. Since the token never expires, the window of opportunity for an attacker is limited only by their ability to discover the link, rather than by a strictly enforced time-to-live (TTL) period. This failure in session lifecycle management necessitates immediate remediation to prevent unauthorized credential modification.",
  "technicalDetails": "The vulnerability resides in the password reset logic of YesWiki, specifically within the checkEmailKey() function. The root cause of the security deficit is the implementation of a static, time-agnostic token verification process. Upon a user requesting a password reset, the application generates a unique token linked to the user account. However, this token is stored without an associated creation timestamp or an expiration epoch. Consequently, the application lacks the necessary metadata to validate whether the request is recent or stale.\nThe attack flow begins with the generation of a reset URL. If an attacker successfully intercepts or recovers this URL from insecure storage—such as local browser history, cached logs, or unauthorized access to an email provider—they can submit the link at any time in the future. Because the checkEmailKey() function does not perform a temporal check, it validates the token exclusively against the current state of the database, confirming only its existence rather than its freshness. If the token remains unused in the database, the checkEmailKey() function successfully validates the request, granting the attacker the ability to define a new password for the associated account.\nThis vulnerability effectively bypasses the expected ephemeral nature of sensitive security tokens. The affected component is the internal authentication management module. Exploitation is possible from any network location where the YesWiki application is reachable, as it does not require authentication or prior knowledge of the user's current password. By providing a valid but stale token, the attacker forces the system to treat the interaction as a legitimate reset request. Post-exploitation, the attacker gains full control over the target account, enabling subsequent unauthorized actions within the YesWiki instance. The lack of an expiration mechanism means that administrative efforts to invalidate these tokens are limited, as the application logic lacks a native automated cleanup or timeout policy for reset tokens."
}
CVE-2026-104468: YesWiki Insufficient Session Expiration (MEDIUM Severity, CVSS: 4.8) | Sceawere