CVE-2026-104463: YesWiki before 4.6.7 Unauthenticated SSRF via ActivityPub Inbox

Published Oct 2, 2026
·
Updated

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their own keyId while supplying internal actor URLs in the body, reaching internal hosts or cloud metadata via blind GET and POST requests.

Affected Software

1 affected component
YesWiki YesWiki<4.6.7

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker does not need authentication or user interaction. They need to send a signed ActivityPub Follow activity to the public forms actor inbox route, using their own keyId while placing an internal actor URL in the activity body.

2

Which systems are exposed?

YesWiki installations before 4.6.7 are affected where the public forms actor inbox route is reachable. The issue can be used to make the YesWiki server send blind GET and POST requests to internal hosts or cloud metadata endpoints.

3

Is a default deployment affected?

The available information identifies the public forms actor inbox route as the exposed entry point, but does not state whether it is enabled or reachable in every default deployment. Verify whether that route is publicly accessible on the affected instance.

4

How can I tell whether an instance may have been targeted?

Review logs for incoming signed ActivityPub Follow requests to the public forms actor inbox route, especially requests whose activity body contains internal, loopback, private-network, or cloud metadata actor URLs. Also review outbound traffic from the YesWiki host for unexpected GET or POST requests to internal services.

5

What can be done while patching is pending?

Restrict public access to the forms actor inbox route if operationally possible, and apply outbound network controls to prevent the YesWiki server from reaching internal networks and cloud metadata services. These measures limit the server-side requests an attacker can induce.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203