Sceawere
Vulnerability Detail
CVE-2026-104468UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Insufficient Session Expiration
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.8
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Insufficient Session Expiration
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.8",
"pubDate": "2026-10-02T12:17:19.540Z",
"pubdate": "2026-10-02T12:17:19.540Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an insufficient session expiration vulnerability within the password reset mechanism. The flaw originates from the absence of temporal validation logic for password reset tokens. By failing to include expiry timestamps, the system treats generated reset links as perpetually valid until a successful password change occurs. This lack of state enforcement poses a critical risk to account security. An attacker who gains unauthorized access to a reset URL—whether through compromised mailboxes, server-side logs, system backups, or browser history—can leverage this persistent link to initiate an account takeover. The vulnerability does not require the attacker to have existing privileges, effectively lowering the barrier for account compromise. Since the token never expires, the window of opportunity for an attacker is limited only by their ability to discover the link, rather than by a strictly enforced time-to-live (TTL) period. This failure in session lifecycle management necessitates immediate remediation to prevent unauthorized credential modification.",
"technicalDetails": "The vulnerability resides in the password reset logic of YesWiki, specifically within the checkEmailKey() function. The root cause of the security deficit is the implementation of a static, time-agnostic token verification process. Upon a user requesting a password reset, the application generates a unique token linked to the user account. However, this token is stored without an associated creation timestamp or an expiration epoch. Consequently, the application lacks the necessary metadata to validate whether the request is recent or stale.\nThe attack flow begins with the generation of a reset URL. If an attacker successfully intercepts or recovers this URL from insecure storage—such as local browser history, cached logs, or unauthorized access to an email provider—they can submit the link at any time in the future. Because the checkEmailKey() function does not perform a temporal check, it validates the token exclusively against the current state of the database, confirming only its existence rather than its freshness. If the token remains unused in the database, the checkEmailKey() function successfully validates the request, granting the attacker the ability to define a new password for the associated account.\nThis vulnerability effectively bypasses the expected ephemeral nature of sensitive security tokens. The affected component is the internal authentication management module. Exploitation is possible from any network location where the YesWiki application is reachable, as it does not require authentication or prior knowledge of the user's current password. By providing a valid but stale token, the attacker forces the system to treat the interaction as a legitimate reset request. Post-exploitation, the attacker gains full control over the target account, enabling subsequent unauthorized actions within the YesWiki instance. The lack of an expiration mechanism means that administrative efforts to invalidate these tokens are limited, as the application logic lacks a native automated cleanup or timeout policy for reset tokens."
}