CVE-2026-104472 | YesWiki up to 4.6.6 Attachment Download download attachment file improper authorization
A vulnerability was found in YesWiki up to 4.6.6. It has been classified as problematic. Affected by this issue is the function attachment of the file Download of the component Attachment Download Handler. The manipulation of the argument File leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-104472. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More