CVE-2026-104467 | YesWiki up to 4.6.6 API Routes /ci/update_config ApiService::isAuthorized authorization

SecurityVulns

A vulnerability was found in YesWiki up to 4.6.6 and classified as critical. Affected by this vulnerability is the function ApiService::isAuthorized of the file /ci/update_config of the component API Routes. Executing a manipulation can lead to authorization bypass.

This vulnerability is handled as CVE-2026-104467. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More