CVE-2026-104459 UNKNOWN

CVE-2026-104459

Published: 2026-10-02

Description

YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST a crafted actor_handle with a numeric host and port to the abonnements view to probe internal HTTPS services and ports.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…