Server-Side Request Forgery in YesWiki Affects Internal Network Security
CVE-2026-104464

8.8HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104464?

YesWiki versions before 4.6.7 are prone to a server-side request forgery (SSRF) vulnerability. This flaw permits unauthenticated attackers to perform unauthorized GET requests by submitting an unvalidated actor URL within the Bazar abonnements sync action. As a result, attackers may exploit this vulnerability to access internal systems or cloud metadata endpoints, potentially chaining this with controlled outbox links to store information in readable Bazar entries. It highlights critical security implications for organizations using YesWiki, necessitating prompt updates to mitigate exposure.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.