CVE-2026-104458 | YesWiki up to 4.6.6 SSRF Guard validateKeyIdUrl keyId server-side request forgery

SecurityVulns

A vulnerability, which was classified as critical, was found in YesWiki up to 4.6.6. The affected element is the function validateKeyIdUrl of the component SSRF Guard. The manipulation of the argument keyId results in server-side request forgery.

This vulnerability is known as CVE-2026-104458. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More