OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104444

HIGH · CVSS 7.1 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

YesWiki versions prior to 4.6.7 are vulnerable to an authorization bypass in the comments API, allowing authenticated low-privilege users to overwrite any page or comment by manipulating the pagetag field in a POST request. This vulnerability can lead to unauthorized content modification and potential data integrity issues. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104444
Severity
HIGH
CVSS
7.1
EPSS
0.27%

Original NVD Description

YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.