AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72804

HIGH · CVSS 8.6 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Versions of SiYuan prior to 3.7.4 are vulnerable due to inadequate validation of the publish-password tier in the getGraph and getLocalGraph endpoints, enabling unauthorized access to block-level content in password-protected documents. This flaw allows anonymous users to retrieve sensitive information without authentication, posing a significant risk to data confidentiality. Organizations using affected versions should prioritize patching to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72804
Severity
HIGH
CVSS
8.6
EPSS
0.26%

Original NVD Description

SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read protected document content and the complete reference topology.