CVE-2026-104456
YesWiki before 4.6.7 Second-Order SQL Injection via ACL Username
CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th
YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a double-quote payload, then load non-admin ACL-filtered listings to read database contents and bypass read ACLs.
| CWE | CWE-89 |
| Vendor | yeswiki |
| Product | yeswiki |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for yeswiki yeswiki
Be the first to know when new high vulnerabilities affecting yeswiki yeswiki are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low
Affected Versions
YesWiki / yeswiki
0 < 4.6.7
References
Credits
๐ manus-use