Sceawere

Vulnerability Detail

CVE-2026-104464UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Server-Side Request Forgery

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal hosts or cloud metadata endpoints and chain attacker-controlled outbox first/next links, with fetched responses stored as readable Bazar entries.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-02T12:17:18.873Z",
  "pubdate": "2026-10-02T12:17:18.873Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in YesWiki prior to version 4.6.7, stemming from improper input validation within the Bazar abonnements sync action. This flaw allows unauthenticated remote attackers to force the underlying server to initiate arbitrary GET requests to internal or external network resources. By supplying a malicious actor URL, an attacker can bypass perimeter defenses to interact with internal services or cloud metadata endpoints. The vulnerability facilitates the retrieval of sensitive information, which is then persisted as readable entries within the Bazar module. Successful exploitation requires no authentication, posing a significant risk to the confidentiality and integrity of the internal network architecture and sensitive data hosted on cloud-based infrastructure.",
  "technicalDetails": "The vulnerability resides in the Bazar component of YesWiki, specifically within the logic handling abonnements (subscription) synchronization. The application fails to adequately sanitize or validate user-supplied actor URLs before passing them to the request-making functionality. This lack of input validation enables an attacker to manipulate the URL parameter to direct the application server to perform GET requests against arbitrary targets, including local loopback addresses (127.0.0.1) or internal network segments that would otherwise be inaccessible from the public internet.\nThe exploitation flow begins with the attacker identifying the specific Bazar sync action endpoint. By injecting a crafted actor URL, the attacker triggers an outbound request from the YesWiki server. The vulnerability allows for the chaining of attacker-controlled outbox 'first' and 'next' links, effectively turning the server into a proxy for multi-stage network reconnaissance or resource extraction. Because the Bazar module is designed to ingest and store responses from these sync operations, the attacker can leverage the application's persistent storage mechanism to capture and read the resulting data returned by the target resource.\nSpecifically, the application's failure to restrict the scheme or hostname of the provided URL permits the exploitation of cloud provider metadata services (e.g., 169.254.169.254). Accessing such endpoints can lead to the exfiltration of instance identities, API keys, or temporary credentials associated with the server. Furthermore, the ability to store the fetched responses as Bazar entries effectively bypasses traditional out-of-band detection mechanisms, as the response content is rendered accessible through the standard application interface. The lack of authentication requirements allows any remote actor to initiate these requests, making the attack surface broad. This SSRF vulnerability facilitates internal service discovery, exploitation of non-public APIs, and potential sensitive data exposure by leveraging the trust relationship inherent in the server's network environment."
}
CVE-2026-104464: YesWiki Server-Side Request Forgery (HIGH Severity, CVSS: 8.6) | Sceawere