Vulnerability Description
YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-x3xh-4hx3-rgm7
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-non-expiring-password-
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-x3xh-4hx3-rgm7
FAQ
What is CVE-2026-104468?
CVE-2026-104468 is a vulnerability with a CVSS score of 4.8 (MEDIUM). YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an un...
How severe is CVE-2026-104468?
CVE-2026-104468 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-104468?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.