Medium severity6.8NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-104469
CVE-2026-104469
Description
YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.