{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/yeswiki--4.6.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-104443"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["YesWiki (\u003c 4.6.7)"],"_cs_severities":["high"],"_cs_tags":["web-application-security","authorization-bypass","cve-2026-104444","web-vulnerability","csrf","yeswiki","sql-injection","vulnerability","webserver","web-application","cve","ssrf","file-upload","remote-code-execution","exfiltration"],"_cs_type":"advisory","_cs_vendors":["YesWiki"],"content_html":"\u003cp\u003eYesWiki versions prior to 4.6.7 are susceptible to an authentication bypass vulnerability residing in the triples delete API. The vulnerability stems from an empty-filter scope bypass, which allows any authenticated user to manipulate or delete semantic triples regardless of defined ownership or permissions. By supplying an empty filter to the triples delete endpoint, an attacker can target critical configuration triples, such as the membership data for the administrative group. Deleting these membership records effectively empties the administrator group, leading to a site-wide administrative lockout. This vulnerability primarily impacts the integrity and availability of YesWiki instances, as unauthorized users can escalate their impact to include a denial of service against the platform administrators.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized modification or deletion of semantic data within the YesWiki application. The most severe consequence is the potential for site-wide administrative lockout, rendering the application unmanageable for legitimate administrators until manual remediation of the affected triples is performed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all YesWiki instances to version 4.6.7 or later to remediate CVE-2026-104443.\u003c/li\u003e\n\u003cli\u003eAudit application logs for anomalous requests to the triples delete API endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict authentication to the YesWiki management interface to trusted users only to reduce the attack surface.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T12:27:18Z","date_published":"2026-10-02T12:24:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-yeswiki-auth-bypass/","summary":"An authentication bypass vulnerability in the YesWiki triples delete API allows authenticated users to delete arbitrary semantic triples, potentially resulting in site-wide denial of service.","title":"YesWiki Triples Delete API Authentication Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-yeswiki-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - YesWiki (\u003c 4.6.7)","version":"https://jsonfeed.org/version/1.1"}