YesWiki Flaws Let Attackers Spoof Identity, Hijack SMTP
Two auth bypass flaws fixed in YesWiki 4.6.7 let unauthenticated attackers forge federated identities via ActivityPub and relay email through the wiki's SMTP server.

The YesWiki team patched two authentication bypass vulnerabilities on October 2, 2026, with the release of version 4.6.7. Both flaws allow unauthenticated requests to perform actions that require identity verification, and one of them sits in the ActivityPub federation layer, where the implementation gap is a recurring failure mode across the fediverse ecosystem.
The higher-severity issue, CVE-2026-104445 (CVSS 8.2, HIGH), is in the ActivityPub inbox handler. ActivityPub relies on HTTP Signatures to authenticate inbound federated requests: a receiving server is supposed to verify that the HTTP signature’s signer matches the activity’s claimed actor. YesWiki’s inbox did not perform that check. An unauthenticated attacker can POST a crafted activity to the inbox and have the wiki process it as if it came from an arbitrary remote actor. The advisory does not enumerate which activity types are affected, but the impact class, forged federated identity, is consistent with unauthorized writes and privilege escalation within the wiki.
The second issue, CVE-2026-104446 (CVSS 6.5, MEDIUM), is in the contact mail AJAX handler. That handler accepts POST requests without verifying that the caller is authenticated, letting anyone submit mail through the wiki’s configured SMTP server. An open relay at the application layer is reliably useful for spam and phishing campaigns, and this one requires no credentials at all.
YesWiki is an open-source collaborative wiki maintained primarily by the French non-profit Outils-Réseaux. The platform sees significant deployment in educational institutions and community organizations across French-speaking Europe. Version 4.6.7 addresses both flaws.
For operators still on an older release: update to 4.6.7. There is no workaround documented for CVE-2026-104445 short of disabling the ActivityPub module; the SMTP relay issue could be partially mitigated by revoking outbound mail access at the server level while an update is staged. Neither advisory indicates active exploitation at this time.
The ActivityPub signature-binding pattern has caught other implementations before. It is the kind of detail that looks correct in a spec reading and incorrect in a code review.
- [ HIGH ]CVE-2026-104445YesWiki ActivityPub inbox auth bypass allows identity spoofing
- [ MEDIUM ]CVE-2026-104446YesWiki contact mail handler allows unauthenticated SMTP relay
Found this useful? Share it.


