Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-73046: SiYuan before 3.7.4 allows unauthorized access to admin panel
CVE-2026-73046 · published 19 days ago
Summary
SiYuan versions before 3.7.4 have a security issue that allows unauthorized users to access the admin panel. This could be exploited by hackers to gain control over the system. To fix this, update SiYuan to version 3.7.4 or later.
What to do
- Update siyuan-note siyuan to version 3.7.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| siyuan-note | siyuan | < 3.7.4 |
Original advisory text
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accep...
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This allows unauthenticated remote attackers to brute-force the admin access code with unlimited automated requests and obtain full RoleAdministrator access to the kernel. A secondary weakness exists because the access code is compared using a non-constant-time string comparison.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-307Improper Restriction of Excessive Authentication Attempts
Timeline
Published15 Aug 2026
Updated3 Sep 2026
First seen15 Aug 2026
Monitor software like this
Free during beta