Incorrect Authorization in SiYuan Affects Document Privacy
CVE-2026-74906
8.7HIGH
What is CVE-2026-74906?
An incorrect authorization vulnerability exists in SiYuan prior to version 3.7.4, impacting eight publish-mode reader-facing endpoints. This flaw enables unauthorized anonymous users to access and read documents explicitly marked as forbidden from being published. The affected endpoints include search, backlink, asset content, saved criteria, recent documents, graph, and tag functionalities, thereby compromising the intended privacy and security of sensitive content.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
