PT-2026-73053 · Siyuan · Siyuan

·

CVE-2026-73046

·

Published

2026-08-15

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description Improper restriction of authentication attempts occurs in the CheckAuth() middleware. The HTTP Basic Authentication branch, which protects most of the /api/* endpoints, accepts the workspace access code Conf.AccessAuthCode as the password but fails to utilize the CAPTCHA/lockout mechanism or increment the failure counter used during cookie or session logins. This allows remote attackers to perform unlimited automated brute-force attacks against the admin access code to gain full RoleAdministrator access to the kernel. Additionally, the access code is verified using a non-constant-time string comparison, which may be susceptible to timing attacks.
Recommendations Update to version 3.7.4 or later.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73046

Affected Products

Siyuan