Sceawere
Vulnerability Detail
CVE-2026-104469UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Session Fixation Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Session Fixation
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-02T12:17:19.703Z",
"pubdate": "2026-10-02T12:17:19.703Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a session fixation vulnerability. This flaw arises from the application's failure to regenerate the PHP session identifier upon successful user authentication. By failing to issue a new session token, the application allows an attacker to maintain a consistent session identifier across the authentication boundary.\nThe vulnerability enables an attacker to hijack the authenticated session of a victim. If an attacker can successfully set or intercept a pre-authentication session cookie—such as one prefixed with 'YesWiki-'—that same identifier remains valid post-authentication. Consequently, the attacker can leverage the victim’s established session to gain unauthorized access to private content or perform administrative and privileged operations under the victim's identity.\nThis represents a significant security risk, as it bypasses standard access control mechanisms. Successful exploitation requires an attacker to successfully influence or acquire the victim's session cookie, potentially through methods such as cross-site scripting (XSS), network sniffing in unencrypted environments, or physical access to the target device. Once the session is fixed, the attacker effectively assumes the identity of the authenticated user for the duration of the session.",
"technicalDetails": "The root cause of this vulnerability is improper session management within the YesWiki authentication workflow. In secure web application design, the session identifier must be rotated or regenerated immediately following a change in the user's authentication state. This ensures that any identifier known to an attacker prior to login becomes invalidated the moment the user successfully authenticates.\nIn affected versions of YesWiki, the application maintains the existing PHP session ID throughout the transition from an unauthenticated state to an authenticated state. Because the session token is preserved, an attacker can 'fix' the session identifier on the victim's browser. This is typically achieved by the attacker setting the 'YesWiki-' session cookie on the target device via client-side scripts, or through man-in-the-middle (MITM) techniques if the transport layer security (TLS) is absent or misconfigured.\nThe exploitation flow proceeds as follows: First, the attacker initiates a request to the YesWiki instance to acquire a valid, unauthenticated session cookie. Second, the attacker forces the victim's browser to utilize this specific session identifier—often referred to as 'seeding' the cookie. Third, the victim performs a legitimate login process through the YesWiki interface. Because the application logic does not invoke a function to destroy the old session and create a new one (such as session_regenerate_id()), the server-side session data associated with that specific ID is elevated to an authenticated status.\nOnce the victim is authenticated, the attacker continues to use the previously seeded session identifier. Since the server recognizes this identifier as the one associated with the now-authenticated user, the attacker's requests are treated as coming from an authorized session. This grants the attacker full access to the victim's privileges, including the ability to read sensitive data, modify private pages, or execute administrative functions available to that user account.\nThe vulnerability resides in the core session handling component of YesWiki. It does not require special administrative privileges to execute, as it targets the authentication mechanism itself. The lack of session rotation is a critical oversight that negates the security benefit of the authentication process itself by allowing for a persistent, predictable session token. This vulnerability persists until the application is updated to a patched version where session management logic is correctly implemented to ensure that every authentication event triggers a secure token renewal."
}