HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-72789 — SiYuan before v3.7.4 fails to properly validate publish access for encrypted not...

·Source: NIST NVD

Updated:

Executive Summary

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.

Analysis

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material. CVSS Score: 8.6. Published: 2026-08-12T20:17:50.270.

Indicators of Compromise (1)

CVE (1)
CVE-2026-72789
Source Attribution

Originally published by NIST NVD on Aug 12, 2026. Verified by: NIST.

Related Threats