Session Cookie Signing Key Disclosure in Siyuan by Siyuan Note
CVE-2026-72794

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72794?

Versions of Siyuan prior to v3.7.4 contain a vulnerability that allows unauthorized users to access the session cookie signing key via the /api/system/getConf endpoint. When the application is in publish mode, attackers can exploit this exposure to retrieve the CookieKey value, enabling them to forge valid session cookies. This vulnerability could lead to user impersonation or unauthorized administrative access, jeopardizing the security of the affected systems.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.