Mmastodon TechnologyCybersecurity first seen 14 h ago, last 14 h ago, peak #12
YesWiki security flaw lets attackers hit admin API routes
Original: 🟠 CVE-2026-104467 - High (8.1) YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuth
A high-severity vulnerability, CVE-2026-104467, has been disclosed in YesWiki, a French open-source wiki software. Versions before 4.6.7 contain an authorization bypass in the ApiService::isAuthorized() function, allowing unauthenticated attackers to call admin-only API routes when public API mode is enabled. Administrators are urged to update to 4.6.7.
Why now: Newly disclosed high-severity vulnerability with an available patch, prompting admins to update
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/749832