Server-Side Request Forgery in YesWiki Affects Internal Network Security
CVE-2026-104464
8.8HIGH
What is CVE-2026-104464?
YesWiki versions before 4.6.7 are prone to a server-side request forgery (SSRF) vulnerability. This flaw permits unauthenticated attackers to perform unauthorized GET requests by submitting an unvalidated actor URL within the Bazar abonnements sync action. As a result, attackers may exploit this vulnerability to access internal systems or cloud metadata endpoints, potentially chaining this with controlled outbox links to store information in readable Bazar entries. It highlights critical security implications for organizations using YesWiki, necessitating prompt updates to mitigate exposure.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
