CVE-2026-104444
Last modified
CVE-2026-104444 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments..
Description
YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104444?
How severe is CVE-2026-104444?
How do I fix CVE-2026-104444?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104438YesWiki before 4.6.7 contains a missing authorization vulner…5.3
- CVE-2026-104439YesWiki before 4.6.7 contains a user enumeration vulnerabili…5.3
- CVE-2026-104440YesWiki before 4.6.7 contains a blind server-side request fo…5.3
- CVE-2026-104441YesWiki before 4.6.7 contains an unauthenticated server-side…5.3
- CVE-2026-104442YesWiki before 4.6.7 contains an unauthenticated server-side…5.8
- CVE-2026-104443YesWiki before 4.6.7 contains an empty-filter scope bypass i…8.1
- CVE-2026-104445YesWiki before 4.6.7 contains an authentication bypass vulne…8.2
- CVE-2026-104446YesWiki before 4.6.7 contains an authentication bypass in th…6.5
- CVE-2026-104447YesWiki before 4.6.7 contains a cross-site request forgery v…7.1
- CVE-2026-104448YesWiki before 4.6.7 contains a cross-site request forgery v…8.1
- CVE-2026-104449YesWiki before 4.6.7 contains an access control vulnerabilit…6.5
- CVE-2026-104450YesWiki before 4.6.7 contains a missing authorization flaw i…6.5
Are you affected by CVE-2026-104444?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
