Vulnerability Description
SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers with publish reader tokens or anonymous access in disabled-auth mode can read templates, snippets, and export artifacts by directly accessing static routes that lack the same restrictions as their REST API counterparts.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fgmr-7w36-9qfq
- https://www.vulncheck.com/advisories/siyuan-before-access-control-bypass-via-sta
FAQ
What is CVE-2026-72796?
CVE-2026-72796 is a vulnerability with a CVSS score of 5.8 (MEDIUM). SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers with publish reader t...
How severe is CVE-2026-72796?
CVE-2026-72796 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72796?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.