Sceawere

Vulnerability Detail

CVE-2026-72804UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
2h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-08-12T20:17:52.383Z",
  "pubdate": "2026-08-12T20:17:52.383Z",
  "executiveSummary": "An authentication bypass vulnerability exists in SiYuan versions prior to v3.7.4, specifically within the publish-password tier validation logic for graph retrieval endpoints. The flaw allows unauthenticated remote attackers to bypass access controls and interact directly with sensitive API functions without supplying the required publish password. Consequently, anonymous readers gain unauthorized access to confidential block-level content and comprehensive reference topologies of password-protected documents. This security failure severely compromises document confidentiality and information privacy within affected deployments. The attack requires network connectivity to the targeted SiYuan instance and knowledge of the specific API endpoints, but completely negates any password protection mechanisms configured by document publishers. Organizations utilizing vulnerable versions face immediate risk of unauthorized data exfiltration, topological mapping of private notes, and exposure of proprietary information stored within the knowledge management platform.",
  "technicalDetails": "The vulnerability resides in the core backend logic governing the getGraph and getLocalGraph API endpoints within SiYuan prior to version v3.7.4. The root cause is the absence of proper input validation and enforcement of the publish-password tier during endpoint execution. When a client issues a request to retrieve graph data or local graph hierarchies, the application logic fails to verify whether the requesting session or payload has successfully authenticated against the associated publish password protection layer. As a result, the access control check is bypassed entirely, allowing unauthenticated, anonymous users to invoke these functions successfully. The attack flow begins with an external entity identifying a SiYuan instance exposing the vulnerable API routes over the network. The attacker crafts HTTP requests targeting the getGraph and getLocalGraph endpoints. Due to the missing validation check in the vulnerable component, the backend processes the request and returns the requested data payloads, which include granular block-level document content and complete inter-document reference topologies. No specialized privileges or prior authentication tokens are required to execute this payload behavior. The post-exploitation impact includes the full disclosure of protected document content, structural knowledge graphs, and metadata relationships that were intended to be restricted to authorized users possessing the correct publish password. The vulnerability affects all SiYuan deployments running software versions prior to v3.7.4 where document publishing with password tiers is utilized."
}
CVE-2026-72804: SiYuan Authentication Bypass Vulnerability (HIGH Severity, CVSS: 8.6) - Sceawere