HIGH 7.1 NVD

CVE-2026-104444

YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overw

YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.

References

Published: 2026-10-02 · Source: NVD · Feed updated: 2026-10-02
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.