PatchSiren cyber security CVE debrief
CVE-2026-72806 siyuan-note CVE debrief
The CVE-2026-72806 record indicates that SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter. This filter fails to check publish password protection when rendering attribute views and database rows, allowing unauthenticated readers to access password-protected document rows, including titles, block IDs, and column values, by calling renderAttributeView without supplying the required password. Affected users should review and apply patches or updates to affected SiYuan installations. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. Users of SiYuan versions before v3.7.4, administrators of SiYuan installations, and security teams monitoring for vulnerabilities in SiYuan should be aware of this issue and take necessary actions.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-26
Who should care
Users of SiYuan versions before v3.7.4, administrators of SiYuan installations, and security teams monitoring for vulnerabilities in SiYuan should be aware of this issue and take necessary actions. This includes reviewing and applying patches or updates to affected SiYuan installations, monitoring for suspicious activity related to SiYuan installations, and implementing compensating controls, such as additional authentication mechanisms. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated and addressed accordingly. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity, indicating that it could have a significant impact on affected systems if exploited. Therefore, it is essential for affected users to prioritize patching and mitigation efforts to minimize potential risks. Additionally, security teams should review and update their vulnerability management processes to ensure that similar issues are addressed promptly in the future. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their systems from potential attacks. It is also recommended that users of SiYuan versions before v3.7.4 consider implementing additional security measures, such as monitoring and detection tools, to help identify and respond to potential threats. Overall, a comprehensive approach to vulnerability management and mitigation is essential to minimizing the risks associated with this issue. Security teams should work closely with affected users and administrators to ensure that patches are applied, and mitigations are implemented in a timely and effective manner. By doing so, organizations can help protect their systems and data from potential attacks and minimize the risk of exploitation. In addition to patching and mitigation efforts, it is also essential for affected users to review and update their incident response plans to ensure that they are prepared to respond to potential security incidents related to this vulnerability. This includes reviewing and updating incident response procedures, conducting regular security audits and risk assessments, and
Technical summary
The FilterViewByPublishAccess filter in SiYuan versions before v3.7.4 fails to check publish password protection when rendering attribute views and database rows. This allows unauthenticated readers to access password-protected document rows, including titles, block IDs, and column values, by calling renderAttributeView without supplying the required password. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. Affected users should review and apply patches or updates to affected SiYuan installations.
Defensive priority
Authenticated attackers could exploit this vulnerability to bypass authentication and access sensitive information.
Recommended defensive actions
- Inventory affected SiYuan installations and verify version numbers.
- Apply patches or updates to affected SiYuan installations.
- Monitor for suspicious activity related to SiYuan installations.
- Implement compensating controls, such as additional authentication mechanisms.
- Review and update incident response plans to ensure preparedness for potential security incidents.
- Conduct regular security audits and risk assessments to identify and address potential vulnerabilities.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE-2026-72806 record indicates that SiYuan versions before v3.7.4 contain an authentication bypass vulnerability. The FilterViewByPublishAccess filter fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document rows, including titles, block IDs, and column values, by calling renderAttributeView without supplying the required password.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72806 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72806
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72806 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72806
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6mcf-g667-w3qv
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-attribute-view
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.