CVE-2026-104469: YesWiki before 4.6.7 Session Fixation via Login in AuthController.php
YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki- session cookie can reuse it after login to access private content and perform actions with the victim's privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YesWikito a version that resolves this vulnerability.Fixed in 4.6.7
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
YesWiki deployments running versions before 4.6.7 are affected. Exploitation targets authenticated users and can expose private content or allow actions using the victim's privileges.
What must an attacker do to exploit the vulnerability?
The attacker must set or obtain a victim's pre-authentication YesWiki session cookie, then have the victim log in using that session. Because the session ID is not regenerated at login, the attacker can reuse the same session after authentication.
Is user interaction required?
Yes. The victim must authenticate after the attacker has set or learned the victim's pre-authentication session cookie.
What is the available remediation?
Update YesWiki to version 4.6.7 or later. The affected behavior is present in versions before 4.6.7.