Medium severity4.8NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-104468
CVE-2026-104468
Description
YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.