Authentication Bypass in SiYuan Notebooks by SiYuan Team
CVE-2026-72789

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72789?

The SiYuan application prior to version 3.7.4 has a critical flaw where encrypted notebooks do not require proper validation for publish access. This vulnerability allows anonymous users to exploit the publish API, granting them the ability to enumerate and access fully decrypted contents of unlocked encrypted notebooks without needing authentication or any key materials. As a result, sensitive information may be exposed to unauthorized individuals, posing significant risks to user privacy and data integrity.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

shirshakopencti
.