HIGH 7.2 NVD
CVE-2026-104443
YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic tr
YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9j7h-ccj2-jxv6
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-scope-bypass-via-triples-delete-
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9j7h-ccj2-jxv6
This high severity vulnerability with a CVSS score of 7.2 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.