Description
SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the visibility list instead of the disabled list. Anonymous visitors can discover and read content from documents explicitly marked as forbidden from publishing by accessing search, backlink, asset content, saved criteria, recent documents, graph, and tag endpoints.
Published: 2026-08-18
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SiYuan versions prior to 3.7.4 expose a flaw in eight publish-mode reader‑facing endpoints that incorrectly apply the visibility list instead of the disabled list when filtering results. This defect allows anonymous visitors to discover and read documents that should be hidden from public view, thereby violating confidentiality. The vulnerability is a typical in‑direct authorization failure and is formally categorized as CWE‑863.

Affected Systems

The flaw affects the SiYuan note-taking application, specifically the version range below v3.7.4. Anyone running an affected version of this product, regardless of installation environment, is potentially exposed.

Risk and Exploitability

The CVSS base score of 8.7 indicates high severity. No EPSS score is currently published and the issue is not listed in the CISA KEV catalog, implying that widespread exploitation may not yet be documented. However, because the flaw can be triggered by unauthenticated users through standard HTTP endpoints, the attack surface is large and the likelihood remains significant for attackers seeking to harvest hidden content.

Generated by OpenCVE AI on August 18, 2026 at 12:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.7.4 or later to apply the vendor’s authorization fix.
  • Configure network or web server rules to deny unauthenticated access to publish-mode endpoints until the upgrade is completed.
  • Disable or limit publish mode features in the affected application until a patch can be applied.

Generated by OpenCVE AI on August 18, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the visibility list instead of the disabled list. Anonymous visitors can discover and read content from documents explicitly marked as forbidden from publishing by accessing search, backlink, asset content, saved criteria, recent documents, graph, and tag endpoints.
Title SiYuan before v3.7.4 Incorrect Authorization via Publish Access
First Time appeared B3log
B3log siyuan
Weaknesses CWE-863
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-18T13:52:07.150Z

Reserved: 2026-08-17T10:48:45.738Z

Link: CVE-2026-74906

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T12:19:30.913

Modified: 2026-08-18T12:19:30.913

Link: CVE-2026-74906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:00:06Z

Weaknesses