cvedb.io
CVE-2026-72789
HIGH · CVSS 8.6
EPSS exploitation probability: 0%
Published 2026-08-12T20:17:50.270 · Last modified 2026-08-12T20:17:50.270

Summary

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.