Authentication Bypass in SiYuan Personal Knowledge Management System
CVE-2026-100646

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100646?

The SiYuan personal knowledge management system, prior to version 3.8.4, exhibits a significant vulnerability due to the failure of its authentication guards to properly validate the HTTP Origin header. This flaw allows attackers to exploit cross-site request patterns that do not include an Origin, granting them unauthorized administrative access. By leveraging this weakness, a malicious user can issue cross-site GET requests from an attacker-controlled web page, not only gaining access to administrative APIs but also enabling the execution of arbitrary scripts within SiYuan's origin context. Furthermore, the vulnerability is compounded by content-type sniffing vulnerabilities within its API, permitting the delivery of attacker-controlled HTML content. Users are strongly advised to upgrade to version 3.8.4 or later to mitigate these risks.

Affected Version(s)

siyuan 0 < 3.8.4

siyuan 3.8.4

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kta1kri
.