CVE-2026-72804: SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4
Event History
Frequently Asked Questions
What is CVE-2026-72804?
CVE-2026-72804 refers to an authentication bypass vulnerability in SiYuan versions before v3.7.4, allowing unauthorized access to protected document content.
What is the severity of CVE-2026-72804?
The severity of CVE-2026-72804 is classified as high with a score of 8.6.
How do I fix CVE-2026-72804?
To fix CVE-2026-72804, upgrade to SiYuan version 3.7.4 or later where the vulnerability has been addressed.
What are the risks associated with CVE-2026-72804?
The risks of CVE-2026-72804 include unauthorized access to sensitive content, potentially leading to data leaks.
Can CVE-2026-72804 be exploited remotely?
Yes, CVE-2026-72804 can be exploited remotely, as it allows anonymous readers to access protected document content.