{"id":"CVE-2026-104469","title":"YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID","summary":"YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-384"],"vendor":"YesWiki","product":"yeswiki","affected":["yeswiki < 4.6.7"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T12:17:19.823","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104469","references":[{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-7fvc-v2hp-5pwh","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-session-fixation-via-login-in-authcontroller-php","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T12:17:44.349Z","slug":"CVE-2026-104469","body":"## Overview\n\nYesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}