CVE-2026-104459: YesWiki before 4.6.7 SSRF via ActivityPub WebFinger actor_handle
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST a crafted actorhandle with a numeric host and port to the abonnements view to probe internal HTTPS services and ports.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
YesWiki versions before 4.6.7 are affected. The exposed request path is the abonnements view through its ActivityPub WebFinger handling.
What does an attacker need to exploit this?
No authentication or user interaction is required. An attacker can POST a crafted actor_handle containing a numeric host and port to cause the server to make HTTPS requests.
What can an attacker do with the SSRF?
The issue can be used to probe internal HTTPS services and ports reachable from the YesWiki server. The provided data indicates confidentiality impact is low and availability impact is low; no integrity impact is listed.
What should be done if patching is not immediately possible?
The provided information identifies the abonnements view and crafted actor_handle input as the exploitation path, but does not specify a supported workaround. Prioritize restricting access to that exposed functionality and limiting the YesWiki server's network reachability to internal HTTPS services where operationally possible.