CVE-2026-104440
Deferred Deferred - Pending Action

Blind SSRF in YesWiki Prior to 4.6.7

Vulnerability report for CVE-2026-104440, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched by curl in loadURLContent() to probe internal networks and reach internal services or metadata endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104440 is a blind Server-Side Request Forgery (SSRF) vulnerability in YesWiki versions before 4.6.7. It exists in the /api/entries/bazarlist route where the idtypeannonce parameter accepts an attacker-controlled URL without proper validation. The application uses a flawed isValidURL() function that always returns true, allowing unauthenticated users to make arbitrary server-side requests via cURL. This enables probing internal networks or accessing internal services.

Detection Guidance

To detect this vulnerability, monitor network traffic for unusual server-side requests originating from your YesWiki instance. Check logs for curl requests to internal or external URLs via the /api/entries/bazarlist endpoint with the idtypeannonce parameter. Use network scanning tools to identify unexpected outbound connections from the server.

Impact Analysis

This vulnerability allows unauthenticated attackers to make server-side requests to internal or external systems. They could scan internal networks, access sensitive internal services, or interact with metadata endpoints. The impact includes potential data leakage, unauthorized access to internal resources, or enabling further attacks on internal infrastructure.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by enabling unauthorized access to sensitive data or internal systems. GDPR requires protecting personal data, while HIPAA mandates securing protected health information. A successful SSRF attack could result in data breaches, violating these regulations and potentially leading to legal penalties or fines.

Mitigation Strategies

Immediately upgrade YesWiki to version 4.6.7 or later. Implement strict URL validation to allow only http/https schemes, resolve DNS, and reject private or reserved IP ranges. Configure curl to pin resolved IPs and disable following redirects. Restrict outbound network access from the server to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104440. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart