OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104445

HIGH · CVSS 8.2 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

YesWiki versions prior to 4.6.7 are vulnerable to an authentication bypass in the ActivityPub inbox, allowing unauthenticated attackers to exploit this flaw using any ActivityPub keypair. This vulnerability enables them to send signed Delete or Update activities that can delete or overwrite other actors' federated entries, posing a significant risk to data integrity. Organizations using YesWiki should prioritize patching this vulnerability to prevent unauthorized data manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104445
Severity
HIGH
CVSS
8.2
EPSS
0.40%

Original NVD Description

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.