CVE-2026-104449EPSS p18.3%
CVE-2026-104449CVE-2026-104449
Description
YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing page, overwriting its body for mass defacement and content destruction.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L |
| EPSS | 0.28% probability of exploitation · percentile 18.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-02 |