PT-2026-76921 · Siyuan · Siyuan

·

CVE-2026-74906

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description An incorrect authorization issue exists in eight reader-facing endpoints used in publish-mode. The system filters results using a visibility list rather than a disabled list, allowing anonymous visitors to discover and read content from documents explicitly marked as forbidden from publishing. This occurs when accessing the following endpoints: search, backlink, asset content, saved criteria, recent documents, graph, and tag.
Recommendations Update SiYuan to version 3.7.4 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74906

Affected Products

Siyuan