OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104443

HIGH · CVSS 8.1 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

YesWiki versions prior to 4.6.7 are vulnerable to an empty-filter scope bypass in the triples delete API, allowing authenticated users to delete or manipulate arbitrary semantic triples without proper authorization. This flaw can lead to the removal of critical admin-group membership, potentially locking out administrators and disrupting site functionality. Organizations using YesWiki should prioritize patching to mitigate the risk of unauthorized access and administrative lockout.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104443
Severity
HIGH
CVSS
8.1
EPSS
0.36%

Original NVD Description

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.