Authentication Bypass Vulnerability in SiYuan by SiYuan Technology
CVE-2026-72806
6.9MEDIUM
What is CVE-2026-72806?
Versions of SiYuan prior to v3.7.4 are vulnerable to an authentication bypass flaw within the FilterViewByPublishAccess filter. This vulnerability allows unauthorized users to access sensitive document rows that are meant to be password-protected. The flaw enables unauthenticated individuals to retrieve critical information—including titles, block IDs, and column values—by invoking the renderAttributeView function without proper password authentication, thus exposing confidential content to unauthorized parties.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
