<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>YesWiki (&lt; 4.6.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/yeswiki--4.6.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 12:24:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/yeswiki--4.6.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>YesWiki Triples Delete API Authentication Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-10-yeswiki-auth-bypass/</link><pubDate>Fri, 02 Oct 2026 12:24:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-yeswiki-auth-bypass/</guid><description>An authentication bypass vulnerability in the YesWiki triples delete API allows authenticated users to delete arbitrary semantic triples, potentially resulting in site-wide denial of service.</description><content:encoded><![CDATA[<p>YesWiki versions prior to 4.6.7 are susceptible to an authentication bypass vulnerability residing in the triples delete API. The vulnerability stems from an empty-filter scope bypass, which allows any authenticated user to manipulate or delete semantic triples regardless of defined ownership or permissions. By supplying an empty filter to the triples delete endpoint, an attacker can target critical configuration triples, such as the membership data for the administrative group. Deleting these membership records effectively empties the administrator group, leading to a site-wide administrative lockout. This vulnerability primarily impacts the integrity and availability of YesWiki instances, as unauthorized users can escalate their impact to include a denial of service against the platform administrators.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in unauthorized modification or deletion of semantic data within the YesWiki application. The most severe consequence is the potential for site-wide administrative lockout, rendering the application unmanageable for legitimate administrators until manual remediation of the affected triples is performed.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all YesWiki instances to version 4.6.7 or later to remediate CVE-2026-104443.</li>
<li>Audit application logs for anomalous requests to the triples delete API endpoint.</li>
<li>Restrict authentication to the YesWiki management interface to trusted users only to reduce the attack surface.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-security</category><category>authorization-bypass</category><category>cve-2026-104444</category><category>web-vulnerability</category><category>csrf</category><category>yeswiki</category><category>sql-injection</category><category>vulnerability</category><category>webserver</category><category>web-application</category><category>cve</category><category>ssrf</category><category>file-upload</category><category>remote-code-execution</category><category>exfiltration</category></item></channel></rss>