{"ok":true,"trend":{"id":749832,"platform":"mastodon","region":"global","key":"🟠 cve-2026-104467 - high (8.1) yeswiki before 4.6.7 contains an authorization bypass vulnerability in apiservice::isauth","title":"🟠 CVE-2026-104467 - High (8.1) YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuth","url":"https://mastodon.social/@thehackerwire/117372038039645720","first_seen":"2026-10-02T15:37:29.884668Z","last_seen":"2026-10-02T15:37:29.884668Z","last_rank":12,"peak_rank":12,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.66078125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A high-severity vulnerability, CVE-2026-104467, has been disclosed in YesWiki, a French open-source wiki software. Versions before 4.6.7 contain an authorization bypass in the ApiService::isAuthorized() function, allowing unauthenticated attackers to call admin-only API routes when public API mode is enabled. Administrators are urged to update to 4.6.7.","why":"Newly disclosed high-severity vulnerability with an available patch, prompting admins to update","tone":"neutral","entities":["YesWiki","CVE-2026-104467"],"summarized_at":"2026-10-02T15:38:21.340073Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1355},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"YesWiki security flaw lets attackers hit admin API routes","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T15:37:29.884668Z","rank":12,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@thehackerwire/117372038039645720","author":"thehackerwire","title":null,"snippet":"🟠 CVE-2026-104467 - High (8.1) YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like…","posted_at":"2026-10-02T15:32:50.284000Z","likes":0}],"elsewhere":[],"window":"7d"}}