---
id: CVE-2026-104439
title: >-
  YesWiki before 4.6.7 contains a user enumeration vulnerability in
  LostPasswordAction.php that allows unauthenticated attackers to confirm
  registered email addresses through differing responses
summary: >-
  YesWiki before 4.6.7 contains a user enumeration vulnerability in
  LostPasswordAction.php that allows unauthenticated attackers to confirm
  registered email addresses through differing responses. Attackers can submit
  emails to the MotDePas…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-204
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T14:17:08.083'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104439'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-892r-45m6-45xc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-user-enumeration-via-lost-password-flow
    label: disclosure@vulncheck.com
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-892r-45m6-45xc'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-02T13:31:22.638912Z'
ingestedAt: '2026-10-02T12:17:44.336Z'
---

## Overview

YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
