Skip to content

Menu
  • Home
Menu

CVE-2026-52767 – YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(…)` accepting `int(-1)`

Posted on September 5, 2026
CVE ID :CVE-2026-52767

Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago

Description :YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP’s openssl_verify() with a loose boolean negation – if (!openssl_verify(…)) { throw … }. PHP’s openssl_verify has four possible return values: 1, 0, -1, and “false”. The -1 row is the bypass: PHP’s truthiness rules make -1 a truthy value, so !(-1) === false, the throw is skipped, and the controller proceeds to processActivity(). Any condition that makes OpenSSL’s EVP_VerifyFinal() return -1 triggers the bypass. The reachable consequence is the controller silently treats a failed verification as success and processes the attacker’s payload. This issue has been patched in version 4.6.6.

Severity: 8.2 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 1

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme