---
id: CVE-2026-104455
title: >-
  YesWiki before 4.6.7 contains an access control bypass vulnerability that
  allows unauthenticated attackers to read restricted page content via the
  recentchangesrssplus RSS action
summary: >-
  YesWiki before 4.6.7 contains an access control bypass vulnerability that
  allows unauthenticated attackers to read restricted page content via the
  recentchangesrssplus RSS action. Attackers can request the xml method of a
  page hosting th…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T14:17:08.610'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104455'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-89vc-h4r4-h25q'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-read-acl-bypass-via-recentchangesrssplus-rss-action
    label: disclosure@vulncheck.com
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-89vc-h4r4-h25q'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-02T13:34:59.050464Z'
ingestedAt: '2026-10-02T12:17:44.341Z'
---

## Overview

YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to retrieve 500-character body excerpts of every latest page, including read-restricted drafts and notes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
