CVE-2026-104468: YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction
YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to account takeover?
Any YesWiki account for which an unused password-reset URL has been exposed is at risk. Reset links may be obtained from mailboxes, logs, backups, or browser history.
What does an attacker need to exploit this issue?
The attacker needs an unused password-reset URL for the target account. No existing account privileges or user interaction are required, but exploitation is rated high complexity because obtaining such a URL is necessary.
Are old reset links still dangerous?
Yes. In affected versions, reset tokens lack expiry timestamps, so an old unused link can be reused to set a new password through checkEmailKey().
How can I determine whether an account may already be affected?
Review whether unused password-reset URLs may have been retained or exposed through mailboxes, application logs, backups, or browser history. Any such URL should be treated as capable of enabling a password change on affected YesWiki versions.
What version resolves the issue?
The issue affects YesWiki versions before 4.6.7. Updating to 4.6.7 or later addresses the missing reset-token expiration behavior.