Authentication Bypass Vulnerability in SiYuan by SiYuan Technology
CVE-2026-72806

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72806?

Versions of SiYuan prior to v3.7.4 are vulnerable to an authentication bypass flaw within the FilterViewByPublishAccess filter. This vulnerability allows unauthorized users to access sensitive document rows that are meant to be password-protected. The flaw enables unauthenticated individuals to retrieve critical information—including titles, block IDs, and column values—by invoking the renderAttributeView function without proper password authentication, thus exposing confidential content to unauthorized parties.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.