CVE-2026-72793: SiYuan before v3.7.4 Information Disclosure via /api/system/getConf
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4 - Configuration
Ensure access-auth codes are configured on the SiYuan instance to prevent escalation to administrator privileges on instances without access-auth codes configured.
SiYuan instances (access-auth codes) access-auth codes configured = configured
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72793?
CVE-2026-72793 is classified as high severity with a score of 8.6.
How do I fix CVE-2026-72793?
To fix CVE-2026-72793, upgrade SiYuan to version 3.7.4 or later.
What vulnerabilities does CVE-2026-72793 present?
CVE-2026-72793 allows information disclosure of sensitive configuration fields, including session-cookie signing keys.
Who is affected by CVE-2026-72793?
Users of SiYuan versions prior to 3.7.4 are affected by CVE-2026-72793.
What type of attack can be executed using CVE-2026-72793?
CVE-2026-72793 enables attackers to forge and tamper with sensitive information by accessing the /api/system/getConf endpoint.