AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72792

MEDIUM · CVSS 5.8 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An information disclosure vulnerability exists in SiYuan versions prior to 3.7.4, allowing unauthenticated users to access tag labels and occurrence counts from password-protected documents via the /api/tag/getTag endpoint. This can lead to the enumeration of sensitive tag vocabulary and internal terminology, potentially exposing confidential information. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72792
Severity
MEDIUM
CVSS
5.8
EPSS
0.24%

Original NVD Description

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.