CVE-2026-104468: YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction

Published Oct 2, 2026
·
Updated

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.

Affected Software

1 affected component
YesWiki YesWiki<4.6.7

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to account takeover?

Any YesWiki account for which an unused password-reset URL has been exposed is at risk. Reset links may be obtained from mailboxes, logs, backups, or browser history.

2

What does an attacker need to exploit this issue?

The attacker needs an unused password-reset URL for the target account. No existing account privileges or user interaction are required, but exploitation is rated high complexity because obtaining such a URL is necessary.

3

Are old reset links still dangerous?

Yes. In affected versions, reset tokens lack expiry timestamps, so an old unused link can be reused to set a new password through checkEmailKey().

4

How can I determine whether an account may already be affected?

Review whether unused password-reset URLs may have been retained or exposed through mailboxes, application logs, backups, or browser history. Any such URL should be treated as capable of enabling a password change on affected YesWiki versions.

5

What version resolves the issue?

The issue affects YesWiki versions before 4.6.7. Updating to 4.6.7 or later addresses the missing reset-token expiration behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203