YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by… (CVE-2026-104464)
YesWiki versions prior to 4.6.7 contain a server-side request forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to make server-side GET requests by providing an unvalidated actor URL to the Bazar abonnements sync action. Exploitation can target internal hosts or cloud metadata endpoints, with attacker-controlled outbox links enabling response data to be stored as readable Bazar entries. The vulnerability has a high severity rating with a CVSS score of 8.6.
AI Analysis
Technical Summary
YesWiki before version 4.6.7 is affected by a server-side request forgery vulnerability (CVE-2026-104464). The vulnerability arises from insufficient validation of actor URLs supplied to the Bazar abonnements sync action, allowing unauthenticated attackers to induce the server to perform arbitrary GET requests. Attackers can leverage this to access internal network resources or cloud metadata endpoints. Additionally, they can manipulate outbox first/next links to chain requests, with the fetched responses stored as readable Bazar entries, potentially exposing sensitive information.
Potential Impact
Successful exploitation allows unauthenticated attackers to make arbitrary server-side GET requests, potentially accessing internal hosts or sensitive cloud metadata endpoints. This can lead to information disclosure (high confidentiality impact), partial integrity compromise (low integrity impact), and partial availability impact (low availability impact) as per the CVSS vector. The vulnerability could facilitate further attacks by revealing internal network structure or credentials.
Mitigation Recommendations
A fix is available in YesWiki version 4.6.7. Users should upgrade to version 4.6.7 or later to remediate this vulnerability. No additional mitigation guidance is provided in the available data. Patch status is confirmed by the version numbering indicating the fix in 4.6.7.
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by… (CVE-2026-104464)
Description
YesWiki versions prior to 4.6.7 contain a server-side request forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to make server-side GET requests by providing an unvalidated actor URL to the Bazar abonnements sync action. Exploitation can target internal hosts or cloud metadata endpoints, with attacker-controlled outbox links enabling response data to be stored as readable Bazar entries. The vulnerability has a high severity rating with a CVSS score of 8.6.
CVSS v3.1
Score 8.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
YesWiki before version 4.6.7 is affected by a server-side request forgery vulnerability (CVE-2026-104464). The vulnerability arises from insufficient validation of actor URLs supplied to the Bazar abonnements sync action, allowing unauthenticated attackers to induce the server to perform arbitrary GET requests. Attackers can leverage this to access internal network resources or cloud metadata endpoints. Additionally, they can manipulate outbox first/next links to chain requests, with the fetched responses stored as readable Bazar entries, potentially exposing sensitive information.
Potential Impact
Successful exploitation allows unauthenticated attackers to make arbitrary server-side GET requests, potentially accessing internal hosts or sensitive cloud metadata endpoints. This can lead to information disclosure (high confidentiality impact), partial integrity compromise (low integrity impact), and partial availability impact (low availability impact) as per the CVSS vector. The vulnerability could facilitate further attacks by revealing internal network structure or credentials.
Mitigation Recommendations
A fix is available in YesWiki version 4.6.7. Users should upgrade to version 4.6.7 or later to remediate this vulnerability. No additional mitigation guidance is provided in the available data. Patch status is confirmed by the version numbering indicating the fix in 4.6.7.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-ghw3-mg2w-7jg2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-104464"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abfee88a43b0b3b89e54bdd
Added to database: 10/02/2026, 17:48:56 UTC
Last enriched: 10/02/2026, 17:57:35 UTC
Last updated: 10/02/2026, 21:46:10 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.