{"id":"CVE-2026-104468","title":"YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps","summary":"YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, …","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-613"],"vendor":"YesWiki","product":"yeswiki","affected":["yeswiki < 4.6.7"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T12:17:19.660","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104468","references":[{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-x3xh-4hx3-rgm7","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-non-expiring-password-reset-tokens-via-lostpasswordaction","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T12:17:44.346Z","slug":"CVE-2026-104468","body":"## Overview\n\nYesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}