AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72810

HIGH · CVSS 8.6 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Versions of SiYuan prior to v3.7.4 are vulnerable to a publish-boundary bypass in WebSocket broadcast sessions, enabling unauthorized access to sensitive content. This flaw allows attackers to establish a WebSocket connection and receive real-time updates, including password-protected and restricted documents, without needing authentication. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72810
Severity
HIGH
CVSS
8.6
EPSS
N/A

Original NVD Description

SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.