Authentication Bypass Vulnerability in YesWiki by YesWiki
CVE-2026-104445

8.8HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104445?

The vulnerability allows unauthenticated attackers to exploit an authentication bypass in the ActivityPub inbox of YesWiki before version 4.6.7. The flaw arises from the system's failure to associate the verified HTTP signature signer with the active actor participating in the ActivityPub protocol. This enables malicious users with any ActivityPub keypair to send unauthorized Delete or Update activities aimed at a mirrored entry's sourceUrl, potentially leading to the deletion or modification of other actors' federated entries. This poses a significant risk to the integrity and confidentiality of user-generated content within YesWiki.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
.