AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72801

HIGH · CVSS 7.5 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Versions of SiYuan prior to 3.7.4 are vulnerable due to the exposure of key-derivation materials and wrapped data keys through unauthenticated endpoints in publish mode. This flaw allows attackers to access sensitive Argon2id parameters and perform unlimited offline cracking attempts on master passwords, significantly compromising the security of encrypted notebooks. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72801
Severity
HIGH
CVSS
7.5
EPSS
0.24%

Original NVD Description

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.