Sceawere

Vulnerability Detail

CVE-2026-72793UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Information Disclosure Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
2h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Insufficiently Protected Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-08-12T20:17:50.837Z",
  "pubdate": "2026-08-12T20:17:50.837Z",
  "executiveSummary": "SiYuan versions prior to v3.7.4 contain an information disclosure vulnerability within the /api/system/getConf endpoint, which fails to properly mask sensitive configuration fields.\nThis security flaw allows anonymous or publish-reader users to retrieve highly sensitive system data, including the session-cookie signing key, the operating system username exposed via the pandoc path, and key material associated with encrypted notebooks.\nThe exposure of the session-cookie signing key enables attackers to forge and tamper with session cookies, allowing unauthorized impersonation of legitimate users.\nFurthermore, on SiYuan instances where access-auth codes are not explicitly configured, successful exploitation of this vulnerability permits complete privilege escalation to administrator privileges.\nThe risk implications are critical, as it compromises session integrity, data confidentiality, and overall administrative control of the affected system without requiring prior authentication or complex exploitation prerequisites.",
  "technicalDetails": "The vulnerability resides in the configuration retrieval mechanism exposed by the /api/system/getConf endpoint in SiYuan versions before v3.7.4.\nThe root cause of the issue is the failure of the application logic to sanitize and mask sensitive configuration parameters before returning them in the API response to the client.\nAffected components include the system configuration handling routines associated with the specified API route.\nAuthentication and privilege requirements for exploitation are minimal; the endpoint can be accessed by anonymous users or users with low-privileged roles such as publish-reader.\nThe network exposure involves the web interface and API listener of the SiYuan application instance.\nThe attack flow proceeds as follows: First, an unauthenticated or low-privileged attacker sends an HTTP request to the /api/system/getConf endpoint. Second, the server processes the request and returns the raw configuration object without stripping sensitive fields. Third, the attacker extracts critical data from the response, specifically the session-cookie signing key, internal file system paths revealing the operating system username via the pandoc configuration, and cryptographic key material for encrypted notebooks.\nArmed with the session-cookie signing key, the attacker can programmatically generate and sign arbitrary session cookies. By injecting these forged cookies into subsequent requests, the attacker can successfully impersonate any user, including high-privilege administrators.\nOn instances deployed without an access-auth code, this impersonation or direct configuration access immediately facilitates full privilege escalation to administrator level, granting complete control over the application environment and access to stored notes and cryptographic materials."
}
CVE-2026-72793: SiYuan Information Disclosure Vulnerability (HIGH Severity, CVSS: 8.6) - Sceawere