Access Control Bypass in SiYuan by SiYuan Team
CVE-2026-72796

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72796?

An access control bypass vulnerability exists in SiYuan versions prior to v3.7.4, allowing unauthorized users to circumvent publish-access controls on the REST API. Attackers with publish reader tokens or those utilizing anonymous access in disabled-auth mode can exploit this flaw to directly access static-file routes. These routes do not enforce the same security restrictions as the REST API counterparts, enabling unauthorized reading of templates, snippets, and export artifacts. It is crucial for users to address this vulnerability and update to the latest version to safeguard against potential exploitation.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.