Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-104445

YesWiki ActivityPub inbox auth bypass allows identity spoofing

YesWiki before 4.6.7 fails to verify that an HTTP Signature signer matches the ActivityPub activity actor, letting unauthenticated attackers perform federated actions as arbitrary remote users.

cat cve-2026-104445.json
Vendor
YesWiki / Outils-Réseaux
Product
YesWiki (before 4.6.7)
CVSS
8.2
EPSS (exploit probability)
0.4%
Status
patched
Published

YesWiki before 4.6.7 contains an authentication bypass in its ActivityPub inbox handler. Inbound federated requests carry an HTTP Signature from the sending server, but the code failed to verify that the signature’s signer matched the claimed activity actor. An unauthenticated remote attacker can submit a crafted POST to the inbox and have it processed as if it originated from any arbitrary actor in the federation.

Affected versions: YesWiki before 4.6.7

Fixed in: YesWiki 4.6.7 (released 2026-10-02)

Mitigation: Update to 4.6.7. If immediate update is not possible, disabling the ActivityPub module removes the attack surface.

References: