Skip to content
feed: live
>_0dayNews
CVE Record
[ MEDIUM ]CVE-2026-104446

YesWiki contact mail handler allows unauthenticated SMTP relay

YesWiki before 4.6.7 does not authenticate requests to the contact mail AJAX handler, allowing unauthenticated attackers to send email through the wiki's configured SMTP server.

cat cve-2026-104446.json
Vendor
YesWiki / Outils-Réseaux
Product
YesWiki (before 4.6.7)
CVSS
6.5
EPSS (exploit probability)
0.4%
Status
patched
Published

YesWiki before 4.6.7 accepts POST requests to the contact mail AJAX handler without requiring authentication. Any unauthenticated attacker can submit a request and relay arbitrary email through the wiki’s configured SMTP server. This exposes the mail server to abuse for spam distribution and phishing campaigns.

Affected versions: YesWiki before 4.6.7

Fixed in: YesWiki 4.6.7 (released 2026-10-02)

Mitigation: Update to 4.6.7. If immediate update is not possible, revoking outbound mail access at the server or firewall level limits relay abuse while an update is staged.

References: