OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104447

HIGH · CVSS 7.1 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

YesWiki versions prior to 4.6.7 are vulnerable to a cross-site request forgery (CSRF) flaw in the autoupdate UpdateAction, enabling attackers to execute unprotected GET requests that can delete installed packages. This vulnerability can be exploited by tricking a logged-in administrator into clicking a malicious link, potentially disrupting core site functionality by removing critical extensions. Organizations using YesWiki should prioritize patching to mitigate the risk of unauthorized package deletions and maintain site integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104447
Severity
HIGH
CVSS
7.1
EPSS
0.13%

Original NVD Description

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like bazar, breaking core site functionality.