CVE-2026-104469: YesWiki before 4.6.7 Session Fixation via Login in AuthController.php

Published Oct 2, 2026
·
Updated

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki- session cookie can reuse it after login to access private content and perform actions with the victim's privileges.

Affected Software

1 affected component
YesWiki YesWiki<4.6.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade YesWiki to a version that resolves this vulnerability.

    Fixed in 4.6.7

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

YesWiki deployments running versions before 4.6.7 are affected. Exploitation targets authenticated users and can expose private content or allow actions using the victim's privileges.

2

What must an attacker do to exploit the vulnerability?

The attacker must set or obtain a victim's pre-authentication YesWiki session cookie, then have the victim log in using that session. Because the session ID is not regenerated at login, the attacker can reuse the same session after authentication.

3

Is user interaction required?

Yes. The victim must authenticate after the attacker has set or learned the victim's pre-authentication session cookie.

4

What is the available remediation?

Update YesWiki to version 4.6.7 or later. The affected behavior is present in versions before 4.6.7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203