---
id: CVE-2026-104446
title: >-
  YesWiki before 4.6.7 contains an authentication bypass in the contact mail
  AJAX handler that allows unauthenticated attackers to send email through the
  wiki's SMTP server
summary: >-
  YesWiki before 4.6.7 contains an authentication bypass in the contact mail
  AJAX handler that allows unauthenticated attackers to send email through the
  wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler
  without …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-306
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:15.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104446'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-36fx-49jj-57rw'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-unauthenticated-open-mail-relay-via-contact-mail-handler
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.338Z'
---

## Overview

YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body for spam and phishing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
