YesWiki Triples Delete API Authentication Bypass
An authentication bypass vulnerability in the YesWiki triples delete API allows authenticated users to delete arbitrary semantic triples, potentially resulting in site-wide denial of service.
CVE search metadata
CVE search record: CVE-2026-104443. Severity: high. CVSS: 8.1. KEV: no. Product: YesWiki (< 4.6.7). Brief: YesWiki Triples Delete API Authentication Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-10-yeswiki-auth-bypass/
What's new
- 1. added coverage for YesWiki (< 4.6.7) Oct 2, 12:27 via nvd
- 2. added detection rule: Detect Exploitation of CVE-2026-104471 - Unauthorized PHP Access in Uploads Oct 2, 12:27 via nvd
- 3. added coverage for YesWiki (< 4.6.7) Oct 2, 12:25 via nvd
- 4. added coverage for YesWiki (< 4.6.7) Oct 2, 12:25 via nvd
- 5. added coverage for YesWiki (< 4.6.7) Oct 2, 12:25 via nvd
YesWiki versions prior to 4.6.7 are susceptible to an authentication bypass vulnerability residing in the triples delete API. The vulnerability stems from an empty-filter scope bypass, which allows any authenticated user to manipulate or delete semantic triples regardless of defined ownership or permissions. By supplying an empty filter to the triples delete endpoint, an attacker can target critical configuration triples, such as the membership data for the administrative group. Deleting these membership records effectively empties the administrator group, leading to a site-wide administrative lockout. This vulnerability primarily impacts the integrity and availability of YesWiki instances, as unauthorized users can escalate their impact to include a denial of service against the platform administrators.
Impact
Successful exploitation results in unauthorized modification or deletion of semantic data within the YesWiki application. The most severe consequence is the potential for site-wide administrative lockout, rendering the application unmanageable for legitimate administrators until manual remediation of the affected triples is performed.
Recommendation
- Upgrade all YesWiki instances to version 4.6.7 or later to remediate CVE-2026-104443.
- Audit application logs for anomalous requests to the triples delete API endpoint.
- Restrict authentication to the YesWiki management interface to trusted users only to reduce the attack surface.
Immediate actions
Upgrade YesWiki to version 4.6.7 or later to patch CVE-2026-104443
Mitigations
Upgrade YesWiki to 4.6.7 or later
CVE-2026-104443
Detection coverage 3
Detect CVE-2026-104444 Exploitation - Authorization Bypass in YesWiki
highDetects unauthorized attempts to edit comments via the YesWiki API by matching patterns indicative of parameter manipulation in the comments route.
Detects CVE-2026-104445 Exploitation - Potential ActivityPub Signature Manipulation
highDetects potential exploitation of CVE-2026-104445 by identifying ActivityPub 'Delete' or 'Update' actions within web server logs that reference unusual sourceUrl parameters.
Detect Exploitation of CVE-2026-104471 - Unauthorized PHP Access in Uploads
highDetects potential exploitation attempts of CVE-2026-104471 by monitoring HTTP requests to the 'files/' directory with a .php extension.
Detection queries are available on the platform. Get full rules →