CVE-2026-104445 PUBLISHED

YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor YesWiki
Product yeswiki
Versions Default: unaffected
  • affected from 0 to 4.6.7 (excl.)
  • Version 4.6.7 is unaffected

Credits

  • arpitjain099 reporter

References

Problem Types

  • Authentication Bypass by Spoofing CWE