CRITICAL 9.2 NVD
CVE-2026-72789
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can e
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-v684-q882-jgmq
- https://www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-encrypted-not
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-12 via NVD.
Risk Timeline
CVE Disclosed2026-08-12 · -1 days ago
Remediation Resources
vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.