YesWiki ActivityPub inbox auth bypass allows identity spoofing
YesWiki before 4.6.7 fails to verify that an HTTP Signature signer matches the ActivityPub activity actor, letting unauthenticated attackers perform federated actions as arbitrary remote users.
- Vendor
- YesWiki / Outils-Réseaux
- Product
- YesWiki (before 4.6.7)
- CVSS
- 8.2
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
YesWiki before 4.6.7 contains an authentication bypass in its ActivityPub inbox handler. Inbound federated requests carry an HTTP Signature from the sending server, but the code failed to verify that the signature’s signer matched the claimed activity actor. An unauthenticated remote attacker can submit a crafted POST to the inbox and have it processed as if it originated from any arbitrary actor in the federation.
Affected versions: YesWiki before 4.6.7
Fixed in: YesWiki 4.6.7 (released 2026-10-02)
Mitigation: Update to 4.6.7. If immediate update is not possible, disabling the ActivityPub module removes the attack surface.
References:
