Improper Authentication Vulnerability in SiYuan Software by SiYuan Note
CVE-2026-73045

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-73045?

SiYuan software prior to version 3.7.4 is susceptible to a vulnerability in the authFilePublishAccess endpoint, where it lacks adequate safeguards against excessive authentication attempts. This flaw permits unauthenticated attackers to perform brute-force attacks by submitting an unlimited number of password guesses without any rate limiting or CAPTCHA requirements. As a result, attackers can potentially gain unauthorized access to password-protected published notebooks, posing significant security risks to the integrity and confidentiality of user data.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.