CVE-2026-52769 | YesWiki up to 4.6.5 HttpSignatureService inbox verifySignature keyId server-side request forgery
A vulnerability classified as problematic has been found in YesWiki up to 4.6.5. Impacted is the function HttpSignatureService::verifySignature of the file /api/forms/{formId}/actor/inbox of the component HttpSignatureService. Performing a manipulation of the argument keyId results in server-side request forgery.
This vulnerability is known as CVE-2026-52769. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More