Remote Code Execution Vulnerability in YesWiki Wiki System
CVE-2026-52769
8.3HIGH
What is CVE-2026-52769?
YesWiki, a PHP-based wiki system, has a vulnerability affecting versions from 4.6.2 to prior to 4.6.6. This issue arises from the public exposure of the POST /api/forms/{formId}/actor/inbox endpoint, which accepts an HTTP Signature header allowing attackers to specify a keyId URL. The vulnerability allows unauthenticated remote attackers to exploit the server by forcing it to make arbitrary outbound HTTP requests, which may lead to disclosure of internal services and sensitive information. The vulnerability can be triggered if ActivityPub is activated on any Bazar form. Users are advised to update to version 4.6.6 or later to mitigate this risk.
Affected Version(s)
yeswiki >= 4.6.2, < 4.6.6
