CVE-2026-72796: SiYuan before v3.7.4 Access Control Bypass via Static Routes
SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers with publish reader tokens or anonymous access in disabled-auth mode can read templates, snippets, and export artifacts by directly accessing static routes that lack the same restrictions as their REST API counterparts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72796?
CVE-2026-72796 has a medium severity rating of 5.8.
How do I fix CVE-2026-72796?
To fix CVE-2026-72796, update SiYuan to version 3.7.4 or later.
What type of vulnerability is CVE-2026-72796?
CVE-2026-72796 is an access control bypass vulnerability.
Who is affected by CVE-2026-72796?
CVE-2026-72796 affects all versions of SiYuan before v3.7.4.
Can attackers exploit CVE-2026-72796 remotely?
Yes, attackers can exploit CVE-2026-72796 remotely if they have publish reader tokens or if anonymous access is enabled.