CVE-2026-104472: YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler
YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YesWikito a version that resolves this vulnerability.Fixed in 4.6.7
Event History
Frequently Asked Questions
Who is exposed to this issue?
YesWiki installations running versions before 4.6.7 are affected where confidential attachments are associated with pages protected by read ACLs. The attacker does not need an account or prior authorization.
What does an attacker need to retrieve a protected attachment?
An attacker needs to know the page tag and the file parameter for the target attachment, then can request the attachment download handler directly. No user interaction or privileges are required.
What data can be exposed?
The issue allows retrieval of attachments from pages whose read ACLs should restrict access. The disclosed impact is confidentiality loss; integrity and availability impacts are not indicated.