PT-2026-67401 · Siyuan · Siyuan

·

CVE-2026-68584

·

Published

2026-08-03

·

Updated

2026-09-10

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.3
Description An authentication bypass exists in publish mode where specific content-returning endpoints do not perform password checks, even though the primary getDoc endpoint is protected. Anonymous attackers can retrieve the full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling the unprotected endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc to bypass the password gate.
Recommendations Update to version 3.7.3 or later. As a temporary workaround, restrict access to the getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc endpoints.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68584
GHSA-7J72-F6WG-CXW6
GHSA-G64V-QQPG-V37H
GO-2026-6382

Affected Products

Siyuan