Local Privilege Escalation in SiYuan by SiYuan Technology
CVE-2026-74801
8.6HIGH
What is CVE-2026-74801?
An issue in SiYuan prior to version 3.7.4 stems from improper handling of workspace directory paths. This oversight allows attackers to create specially crafted workspace directories with command metacharacters that, when processed, activate the elevated elevator.exe helper process. This can lead to arbitrary command execution with administrator privileges after User Account Control (UAC) approval, potentially compromising the system's security.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
