PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72788 siyuan-note CVE debrief

The CVE-2026-72788 vulnerability affects SiYuan versions before v3.7.4, allowing unauthenticated attackers to retrieve sensitive information. The vulnerability class is information disclosure, with a likely operational impact of data exposure. Source confidence is limited to the provided CVE record and NVD entry. Review context suggests that administrators of SiYuan installations and security teams should be aware of this vulnerability.

Vendor
siyuan-note
Product
siyuan
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-26
Advisory published
2026-08-12
Advisory updated
2026-08-26

Who should care

Users of SiYuan versions before v3.7.4, administrators of SiYuan installations, security teams responsible for monitoring and protecting against information disclosure vulnerabilities, and operators of affected platforms should be aware of this vulnerability and take necessary actions to protect their systems. Vulnerability management and security teams should prioritize patching or mitigating this vulnerability to prevent potential data exposure. Affected asset owners should review and limit the exposure of open documents, search terms, notebook paths, and private asset locations. Security teams should also monitor for any unauthorized access to sensitive information and verify the integrity of their SiYuan installations. Additionally, platform administrators should ensure that compensating controls are in place for exposed systems while remediation is scheduled and verified. Those responsible for change management should track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory managers should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Those in charge of monitoring and detection should check relevant logs for exposed assets that need extra review. Those responsible for source tracking should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Finally, security teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. This involves coordinating with vendors, testing patches, and implementing them in a timely manner to minimize potential impact. By taking these steps, organizations can effectively manage the risks associated with CVE-2026-72788 and protect their sensitive information from unauthorized disclosure. The vulnerability management process should include verifying the affected scope, assessing the severity of the vulnerability, and implementing appropriate controls to mitigate the risk. This may involve updating SiYuan to version v3.7.4 or later, restricting access to the getConf endpoint, and monitoring for any una

Technical summary

The information disclosure vulnerability in SiYuan versions before v3.7.4 is caused by the UILayout filter failing to properly restrict administrator workspace state from publish readers. This allows unauthenticated attackers to retrieve sensitive information by calling the getConf endpoint without authentication. The vulnerability has a CVSS score of 6.9, indicating a medium severity level. Affected products include SiYuan versions before v3.7.4.

Defensive priority

CVE-2026-72788 is rated MEDIUM with a CVSS score of 6.9; unauthenticated attackers can exploit this vulnerability to retrieve sensitive information.

Recommended defensive actions

  • Review and apply the vendor's remediation for SiYuan versions before v3.7.4.
  • Restrict access to the getConf endpoint to authenticated users only.
  • Monitor for any unauthorized access to sensitive information.
  • Update SiYuan to version v3.7.4 or later.
  • Verify and limit the exposure of open documents, search terms, notebook paths, and private asset locations.

Evidence notes

The CVE-2026-72788 details indicate that SiYuan versions before v3.7.4 have an information disclosure vulnerability in the UILayout filter. This vulnerability allows unauthenticated attackers to retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint without authentication. The CVSS score is 6.9, indicating a medium severity level.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72788 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72788

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72788 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72788

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.