CVE-2026-104446
Last modified
CVE-2026-104446 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body for spam and phishing..
Description
YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body for spam and phishing.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104446?
How severe is CVE-2026-104446?
How do I fix CVE-2026-104446?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104440YesWiki before 4.6.7 contains a blind server-side request fo…5.3
- CVE-2026-104441YesWiki before 4.6.7 contains an unauthenticated server-side…5.3
- CVE-2026-104442YesWiki before 4.6.7 contains an unauthenticated server-side…5.8
- CVE-2026-104443YesWiki before 4.6.7 contains an empty-filter scope bypass i…8.1
- CVE-2026-104444YesWiki before 4.6.7 contains an authorization bypass vulner…7.1
- CVE-2026-104445YesWiki before 4.6.7 contains an authentication bypass vulne…8.2
- CVE-2026-104447YesWiki before 4.6.7 contains a cross-site request forgery v…7.1
- CVE-2026-104448YesWiki before 4.6.7 contains a cross-site request forgery v…8.1
- CVE-2026-104449YesWiki before 4.6.7 contains an access control vulnerabilit…6.5
- CVE-2026-104450YesWiki before 4.6.7 contains a missing authorization flaw i…6.5
- CVE-2026-104451YesWiki before 4.6.7 contains a cross-site request forgery v…4.3
- CVE-2026-104452YesWiki before 4.6.7 contains a cross-site request forgery v…5.4
Are you affected by CVE-2026-104446?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
