---
id: CVE-2026-104468
title: >-
  YesWiki before 4.6.7 contains an insufficient session expiration vulnerability
  that allows attackers to reuse old password reset links because tokens lack
  expiry timestamps
summary: >-
  YesWiki before 4.6.7 contains an insufficient session expiration vulnerability
  that allows attackers to reuse old password reset links because tokens lack
  expiry timestamps. Attackers who obtain an unused reset URL from mailboxes,
  logs, …
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-613
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:19.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104468'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-x3xh-4hx3-rgm7'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-non-expiring-password-reset-tokens-via-lostpasswordaction
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.346Z'
---

## Overview

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
