High severity7.0NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-104463
CVE-2026-104463
Description
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their own keyId while supplying internal actor URLs in the body, reaching internal hosts or cloud metadata via blind GET and POST requests.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.