Server-Side Request Forgery in YesWiki Affects Internal Services
CVE-2026-104459
6.9MEDIUM
What is CVE-2026-104459?
A vulnerability in YesWiki prior to version 4.6.7 allows unauthenticated attackers to exploit a server-side request forgery (SSRF) flaw in the WebfingerService. By crafting a specific actor_handle that includes a numeric host and port, attackers can send HTTPS requests from the server to internal hosts. This opens up the potential for probing internal services and ports, creating significant security risks for affected users.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
