Improper Authentication Vulnerability in SiYuan Software by SiYuan Note
CVE-2026-73045
8.7HIGH
What is CVE-2026-73045?
SiYuan software prior to version 3.7.4 is susceptible to a vulnerability in the authFilePublishAccess endpoint, where it lacks adequate safeguards against excessive authentication attempts. This flaw permits unauthenticated attackers to perform brute-force attacks by submitting an unlimited number of password guesses without any rate limiting or CAPTCHA requirements. As a result, attackers can potentially gain unauthorized access to password-protected published notebooks, posing significant security risks to the integrity and confidentiality of user data.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
