PT-2026-71236 · Siyuan · Siyuan

·

CVE-2026-72794

·

Published

2026-08-12

·

Updated

2026-09-10

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions siyuan versions prior to 3.7.4
Description In publish mode, the /api/system/getConf endpoint exposes the CookieKey variable, which is the cryptographic key used to sign session cookies, to unauthenticated users or those with RoleReader permissions. This occurs because the masking process for this endpoint fails to remove the secret key, unlike the configuration-export endpoint. An attacker can retrieve this key to forge or modify session cookies that the server accepts as authentic. Depending on the server configuration, such as when no access-auth code is set, this can lead to user impersonation or unauthorized administrative access.
Recommendations Update siyuan to version 3.7.4 or later. As a temporary mitigation, restrict access to the /api/system/getConf endpoint.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72794
GHSA-34FJ-MWM6-FJFG
GHSA-HG4J-W33M-P7G4
GO-2026-6420

Affected Products

Siyuan