---
id: CVE-2026-104469
title: >-
  YesWiki before 4.6.7 contains a session fixation vulnerability that allows
  attackers to hijack authenticated sessions because login does not regenerate
  the PHP session ID
summary: >-
  YesWiki before 4.6.7 contains a session fixation vulnerability that allows
  attackers to hijack authenticated sessions because login does not regenerate
  the PHP session ID. Attackers who set or learn a victim's pre-authentication
  YesWiki-…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-384
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:19.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104469'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-7fvc-v2hp-5pwh'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-session-fixation-via-login-in-authcontroller-php
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.349Z'
---

## Overview

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
