PT-2026-71251 · Siyuan · Siyuan

·

CVE-2026-72809

·

Published

2026-08-12

·

Updated

2026-09-10

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description An authentication bypass exists in the kernel's CheckAuth() function. The system grants the RoleAdministrator role to any request where the RemoteAddr is the loopback address (127.0.0.1) for specific endpoints, including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/*, and /export/*. This bypass occurs outside the access authentication code gate, meaning it remains effective even if an access auth code is configured. When a fixed-port reverse proxy forwards requests to the kernel over loopback without an authentication token and without configured trusted proxies, the kernel perceives the RemoteAddr as 127.0.0.1. If this proxy is bound to a network interface, a remote unauthenticated attacker could potentially obtain administrator access to the affected endpoints, although this specific remote forwarding behavior has only been identified via code inspection and not reproduced end-to-end.
Recommendations Update to version 3.7.4 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72809
GHSA-3MP7-4RH5-JRV9
GHSA-8WX9-J7J5-H9VP
GO-2026-6386

Affected Products

Siyuan