---
id: CVE-2026-104443
title: >-
  YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples
  delete API that allows any authenticated user to delete or forge arbitrary
  semantic triples regardless of ownership
summary: >-
  YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples
  delete API that allows any authenticated user to delete or forge arbitrary
  semantic triples regardless of ownership. Attackers can send an empty filter
  to the trip…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-863
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T14:17:08.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104443'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9j7h-ccj2-jxv6'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-scope-bypass-via-triples-delete-api
    label: disclosure@vulncheck.com
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9j7h-ccj2-jxv6'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-02T13:32:12.569494Z'
ingestedAt: '2026-10-02T12:17:44.337Z'
---

## Overview

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
