Remote Code Execution Vulnerability in YesWiki Wiki System
CVE-2026-52769

8.3HIGH

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-52769?

YesWiki, a PHP-based wiki system, has a vulnerability affecting versions from 4.6.2 to prior to 4.6.6. This issue arises from the public exposure of the POST /api/forms/{formId}/actor/inbox endpoint, which accepts an HTTP Signature header allowing attackers to specify a keyId URL. The vulnerability allows unauthenticated remote attackers to exploit the server by forcing it to make arbitrary outbound HTTP requests, which may lead to disclosure of internal services and sensitive information. The vulnerability can be triggered if ActivityPub is activated on any Bazar form. Users are advised to update to version 4.6.6 or later to mitigate this risk.

Affected Version(s)

yeswiki >= 4.6.2, < 4.6.6

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.