Vulnerability Description
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal hosts or cloud metadata endpoints and chain attacker-controlled outbox first/next links, with fetched responses stored as readable Bazar entries.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-wcjp-v62j-p5xm
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-ssrf-via-bazar-abonnem
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-wcjp-v62j-p5xm
FAQ
What is CVE-2026-104464?
CVE-2026-104464 is a vulnerability with a CVSS score of 8.6 (HIGH). YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abon...
How severe is CVE-2026-104464?
CVE-2026-104464 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-104464?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.