Description
YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.
Published: 2026-10-02
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises because YesWiki does not properly correlate the HTTP signature signer with the declared actor in the ActivityPub inbox. An unauthenticated attacker possessing any valid ActivityPub key pair can craft signed Delete or Update activities addressed to another actor’s federated entry. When the protected content’s sourceUrl is referenced, the server processes the request without verifying that the actor matches the signed key, allowing deletion or overwriting of another user’s content.

Affected Systems

Affected versions are all releases of YesWiki prior to 4.6.7; the issue has not been fixed except by upgrading to 4.6.7 or later. The product is the YesWiki content‑management platform distributed under the name yeswiki. No sub‑variant or operating‑system specifics are given, so any installation of YesWiki that includes the ActivityPub inbox before 4.6.7 is potentially vulnerable.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is classified as high severity, and the EPSS score is not available. Because the flaw permits an unauthenticated actor to supply a signed request, the attack vector is remote network access; an adversary only needs to send an ActivityPub message with a fabricated signature. The flaw is listed as CWE–290 and is not present in CISA’s KEV catalog.

Generated by OpenCVE AI on October 2, 2026 at 12:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to 4.6.7 or later to apply the authentication‑binding fix.
  • If an immediate upgrade is not feasible, restrict the ActivityPub inbox to accept signed messages only from trusted actors and reject any Delete or Update requests that reference non‑own source URLs.
  • After remediation, audit federated content for unintended deletions or updates, and revoke any Actor keys that may have been used by an attacker.

Generated by OpenCVE AI on October 2, 2026 at 12:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.
Title YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-290
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:19.058Z

Reserved: 2026-10-02T00:53:03.851Z

Link: CVE-2026-104445

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:15.657

Modified: 2026-10-02T12:17:15.770

Link: CVE-2026-104445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:05Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing