Skip to content
Threat Feed
high advisory

YesWiki Triples Delete API Authentication Bypass

An authentication bypass vulnerability in the YesWiki triples delete API allows authenticated users to delete arbitrary semantic triples, potentially resulting in site-wide denial of service.

CVE search metadata

CVE search record: CVE-2026-104443. Severity: high. CVSS: 8.1. KEV: no. Product: YesWiki (< 4.6.7). Brief: YesWiki Triples Delete API Authentication Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-10-yeswiki-auth-bypass/

What's new

  • 1. added coverage for YesWiki (< 4.6.7) Oct 2, 12:27 via nvd
  • 2. added detection rule: Detect Exploitation of CVE-2026-104471 - Unauthorized PHP Access in Uploads Oct 2, 12:27 via nvd
  • 3. added coverage for YesWiki (< 4.6.7) Oct 2, 12:25 via nvd
  • 4. added coverage for YesWiki (< 4.6.7) Oct 2, 12:25 via nvd
  • 5. added coverage for YesWiki (< 4.6.7) Oct 2, 12:25 via nvd

YesWiki versions prior to 4.6.7 are susceptible to an authentication bypass vulnerability residing in the triples delete API. The vulnerability stems from an empty-filter scope bypass, which allows any authenticated user to manipulate or delete semantic triples regardless of defined ownership or permissions. By supplying an empty filter to the triples delete endpoint, an attacker can target critical configuration triples, such as the membership data for the administrative group. Deleting these membership records effectively empties the administrator group, leading to a site-wide administrative lockout. This vulnerability primarily impacts the integrity and availability of YesWiki instances, as unauthorized users can escalate their impact to include a denial of service against the platform administrators.

Impact

Successful exploitation results in unauthorized modification or deletion of semantic data within the YesWiki application. The most severe consequence is the potential for site-wide administrative lockout, rendering the application unmanageable for legitimate administrators until manual remediation of the affected triples is performed.

Recommendation

  1. Upgrade all YesWiki instances to version 4.6.7 or later to remediate CVE-2026-104443.
  2. Audit application logs for anomalous requests to the triples delete API endpoint.
  3. Restrict authentication to the YesWiki management interface to trusted users only to reduce the attack surface.

Immediate actions

Upgrade YesWiki to version 4.6.7 or later to patch CVE-2026-104443

IT Operations 48h

Mitigations

Upgrade YesWiki to 4.6.7 or later

immediate IT Operations

CVE-2026-104443

Detection coverage 3

Detect CVE-2026-104444 Exploitation - Authorization Bypass in YesWiki

high

Detects unauthorized attempts to edit comments via the YesWiki API by matching patterns indicative of parameter manipulation in the comments route.

sigma tactics: privilege_escalation techniques: T1068 sources: webserver

Detects CVE-2026-104445 Exploitation - Potential ActivityPub Signature Manipulation

high

Detects potential exploitation of CVE-2026-104445 by identifying ActivityPub 'Delete' or 'Update' actions within web server logs that reference unusual sourceUrl parameters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detect Exploitation of CVE-2026-104471 - Unauthorized PHP Access in Uploads

high

Detects potential exploitation attempts of CVE-2026-104471 by monitoring HTTP requests to the 'files/' directory with a .php extension.

sigma tactics: initial_access techniques: T1203 sources: webserver

Detection queries are available on the platform. Get full rules →