CVE-2026-72789: SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72789?
The severity of CVE-2026-72789 is rated high with a score of 8.6.
How do I fix CVE-2026-72789?
To fix CVE-2026-72789, update SiYuan to version 3.7.4 or later.
What impact does CVE-2026-72789 have on my data?
CVE-2026-72789 allows anonymous users to retrieve fully decrypted content from unlocked encrypted notebooks without authentication.
Who is affected by CVE-2026-72789?
Any user of SiYuan versions prior to 3.7.4 that has encrypted notebooks is affected by CVE-2026-72789.
Is there a workaround for CVE-2026-72789 until I can update?
There is no official workaround for CVE-2026-72789; upgrading to the latest version is the recommended action.