CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104469

MEDIUMCVSS 6.8NVD feed

Published 2 October 2026 · tracked since 3 October 2026

Description

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private con

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-104469 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104469

MEDIUMCVSS 6.8NVD feed

Published 2 October 2026 · tracked since 3 October 2026

Description

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private con

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]