Sceawere

Vulnerability Detail

CVE-2026-104445UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki ActivityPub Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-02T12:17:15.657Z",
  "pubdate": "2026-10-02T12:17:15.657Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an authentication bypass vulnerability within the ActivityPub protocol implementation. The flaw exists due to a logic error in the handling of HTTP signatures, specifically the failure to cryptographically bind a verified signer to the corresponding ActivityPub actor object.\nThis vulnerability allows any remote attacker possessing a valid ActivityPub keypair to bypass authentication mechanisms and issue unauthorized commands. By crafting malicious activities, an attacker can manipulate or destroy federated data entries, specifically Delete or Update activities targeting mirrored entries via the sourceUrl parameter.\nThe impact is significant, as it enables unauthorized data modification and content deletion across federated instances, potentially leading to service degradation or loss of data integrity. This flaw does not require the attacker to have prior authentication or authorization within the target YesWiki instance, only the ability to generate a signed HTTP request acceptable by the inbox. The lack of validation between the signing key and the actor identity constitutes a critical failure in the federated identity management layer.",
  "technicalDetails": "The vulnerability resides in the ActivityPub inbox processing component of YesWiki, which is responsible for ingesting incoming federated activities. The core issue is an improper validation sequence where the application performs HTTP signature verification but fails to verify the relationship between the key owner and the actor performing the action.\nSpecifically, when an ActivityPub 'Delete' or 'Update' activity is received, the application verifies the HTTP signature against the public key provided. However, the system fails to verify that the 'actor' field in the activity JSON object corresponds to the owner of the public key used for the HTTP signature. This decoupling effectively allows an attacker to sign an activity with their own legitimate key pair while claiming to be any arbitrary actor registered in the federation.\nThe attack flow begins with the attacker identifying a target mirrored entry within the YesWiki instance, specifically obtaining the 'sourceUrl' associated with the content. The attacker constructs a malicious ActivityPub payload—such as an 'Update' activity designed to overwrite the target entry content or a 'Delete' activity intended to remove the entry from the database. The attacker signs this payload using their own valid ActivityPub private key and transmits it to the YesWiki inbox endpoint via a POST request.\nUpon receipt, the YesWiki inbox mechanism executes the signature verification logic, which returns a success status because the signature is mathematically valid for the attacker’s key. Because the code fails to perform a secondary validation check to ensure the 'actor' identity matches the signature owner, the application trusts the contents of the malicious activity payload.\nConsequently, the YesWiki back-end processes the 'Delete' or 'Update' command as if it were an authorized request from the legitimate owner of the sourceUrl content. This leads to arbitrary data manipulation or deletion. The exposure is network-based, reachable by any federated peer that can communicate with the YesWiki instance. Since the vulnerability is located at the protocol processing layer, it bypasses standard session-based authentication entirely. This flaw impacts all YesWiki instances below version 4.6.7 that have ActivityPub features enabled."
}
CVE-2026-104445: YesWiki ActivityPub Authentication Bypass (HIGH Severity, CVSS: 8.2) | Sceawere