CVE-2026-52766

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl='*') on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users. This issue has been patched in version 4.6.6.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 00:17

Updated : 2026-09-09 17:17


NVD link : CVE-2026-52766

Mitre link : CVE-2026-52766

CVE.ORG link : CVE-2026-52766


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions

CWE-862

Missing Authorization