Authentication Bypass Vulnerability in SiYuan by SiYuan Developer
CVE-2026-72809

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72809?

SiYuan versions prior to 3.7.4 contain a vulnerability that allows unauthorized administrative access through specific endpoints, including /api/system/exit and /assets/*. This occurs due to the CheckAuth function improperly handling requests made from the loopback address (127.0.0.1), which bypasses access controls even when an authentication token is configured. Furthermore, when utilizing a fixed-port reverse proxy, requests can be forwarded to the kernel without proper authentication, potentially allowing a remote attacker to exploit this flaw for unauthorized admin privileges.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.