Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries. | |
| Title | YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing | |
| First Time appeared |
Yeswiki
Yeswiki yeswiki |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yeswiki
Yeswiki yeswiki |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T11:38:19.058Z
Reserved: 2026-10-02T00:53:03.851Z
Link: CVE-2026-104445
No data.
Status : Deferred
Published: 2026-10-02T12:17:15.657
Modified: 2026-10-02T12:17:15.770
Link: CVE-2026-104445
No data.
OpenCVE Enrichment
Updated: 2026-10-02T13:30:05Z
-
CWE-290
Authentication Bypass by Spoofing