CVE-2026-104463
Deferred Deferred - Pending Action

Server-Side Request Forgery in YesWiki Prior to 4.6.7

Vulnerability report for CVE-2026-104463, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their own keyId while supplying internal actor URLs in the body, reaching internal hosts or cloud metadata via blind GET and POST requests.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yeswiki yeswiki to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104463 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in YesWiki versions 4.6.6 and below. It exists in the public ActivityPub inbox route, which accepts signed Follow activities without validating the JSON body's actor or to fields. Attackers exploit this by signing requests with their own keyId while specifying internal actor URLs, forcing the server to make blind GET and POST requests to internal hosts or cloud metadata endpoints like http://169.254.169.254/. The vulnerability requires ActivityPub to be enabled on at least one Bazar form.

Detection Guidance

To detect this vulnerability, check if ActivityPub is enabled on any Bazar form by querying GET /api/forms. Monitor server logs for unusual outbound requests to internal hosts or cloud metadata endpoints like 169.254.169.254. Look for signed Follow activities sent to the public forms actor inbox route.

Impact Analysis

This vulnerability allows unauthenticated attackers to access internal resources or cloud metadata services by tricking the server into making requests to unintended targets. It may also enable blind data extraction through timing oracles in error messages. The impact includes potential exposure of sensitive internal information and disruption of service availability.

Compliance Impact

This SSRF vulnerability could potentially expose sensitive data by allowing attackers to access internal hosts or cloud metadata endpoints, which may contain confidential information. This could violate GDPR's data protection requirements or HIPAA's safeguards for protected health information if such data is accessed or exfiltrated.

Mitigation Strategies

Upgrade YesWiki to version 4.6.7 or later. Validate actor/to/recipient URLs against a scheme allowlist and reject private/loopback/link-local IPs before any inbound fetch. Disable ActivityPub on Bazar forms if not needed. Monitor network traffic for unexpected internal requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104463. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart