CVE-2026-100635: SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie

Published Sep 26, 2026
·
Updated

SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoints without knowing the account password.

Affected Software

1 affected component
SiYuan SiYuan<3.8.4

Event History

Sep 26, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Deployments using the SiYuan publish service over plaintext HTTP are exposed, particularly where an attacker can observe traffic between a user and the service. The issue affects versions before v3.8.4.

2

What does an attacker need to exploit it?

An attacker must be able to act on-path and observe a Basic Auth exchange over plaintext HTTP. They can capture the valid publish-visitor-session-id cookie and replay it to authenticated publish endpoints without the account password.

3

Does the issue affect HTTPS-only deployments?

The provided information identifies session cookies issued over plaintext HTTP connections as the exposure condition. It does not indicate that an attacker can capture and replay the cookie from an HTTPS-protected exchange.

4

What can be done if upgrading is not immediately possible?

Avoid serving the publish service over plaintext HTTP, since the described attack depends on observing HTTP traffic. Restrict access to trusted networks where possible until the deployment can be upgraded to v3.8.4 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203