CVE-2026-104442
Deferred Deferred - Pending Action

Unauthenticated SSRF in YesWiki via Syndication Action

Vulnerability report for CVE-2026-104442, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104442 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in YesWiki versions before 4.6.7. Attackers can exploit the syndication action via the render handler's content parameter to make the server fetch arbitrary URLs without authentication. The server uses SimplePie to fetch content without validating URLs, allowing attackers to target internal hosts, read fetched content in responses, and download feed enclosures into the files directory.

Detection Guidance

Check YesWiki versions prior to 4.6.7 by running: grep -r 'yeswiki' /path/to/yeswiki/version or check the footer of your YesWiki site. Monitor network logs for unexpected outbound requests to internal or external hosts from the YesWiki server. Look for unusual file writes in the files/ directory of YesWiki installations.

Impact Analysis

This vulnerability allows attackers to scan internal networks, interact with internal services like cloud metadata endpoints, and exfiltrate sensitive data through rendered feed items. Attackers can also write arbitrary files to the server's files directory by exploiting feed enclosures. Since no authentication is required, the risk of exploitation is high.

Compliance Impact

This SSRF vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Exfiltration of internal data or interaction with restricted services may result in compliance breaches, potential fines, and reputational damage.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later immediately. If upgrading is not possible, restrict access to the syndication action by requiring authentication or disabling it. Configure firewalls to block outbound requests from the YesWiki server to internal networks. Validate all URLs in the syndication action to allow only trusted schemes and hosts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104442. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart