Authentication Bypass Vulnerability in YesWiki by YesWiki
CVE-2026-104445
8.8HIGH
What is CVE-2026-104445?
The vulnerability allows unauthenticated attackers to exploit an authentication bypass in the ActivityPub inbox of YesWiki before version 4.6.7. The flaw arises from the system's failure to associate the verified HTTP signature signer with the active actor participating in the ActivityPub protocol. This enables malicious users with any ActivityPub keypair to send unauthorized Delete or Update activities aimed at a mirrored entry's sourceUrl, potentially leading to the deletion or modification of other actors' federated entries. This poses a significant risk to the integrity and confidentiality of user-generated content within YesWiki.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
