OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104464

HIGH · CVSS 8.6 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

YesWiki versions prior to 4.6.7 are vulnerable to a server-side request forgery (SSRF) flaw that allows unauthenticated attackers to send GET requests to internal servers by exploiting an unvalidated actor URL in the Bazar abonnements sync action. This vulnerability can lead to unauthorized access to sensitive internal resources and cloud metadata, potentially compromising system integrity and confidentiality. Organizations using YesWiki should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104464
Severity
HIGH
CVSS
8.6
EPSS
0.29%

Original NVD Description

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal hosts or cloud metadata endpoints and chain attacker-controlled outbox first/next links, with fetched responses stored as readable Bazar entries.