CVE-2026-72796

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/08/2026
Last modified:
26/08/2026

Description

SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers with publish reader tokens or anonymous access in disabled-auth mode can read templates, snippets, and export artifacts by directly accessing static routes that lack the same restrictions as their REST API counterparts.