CVE-2026-72797: Missing Authorization in siyuan-note siyuan
SiYuan versions before v3.7.4 have an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint. This endpoint returns encrypted notebook identifiers, names, and lock states without proper publish-access filtering. As a result, anonymous users and publish-mode accounts can enumerate all encrypted notebooks and their unlock status, exposing sensitive notebook names and decryption states in memory.
AI Analysis
Technical Summary
CVE-2026-72797 is an information disclosure vulnerability affecting SiYuan note-taking software versions prior to v3.7.4. The vulnerability exists in the getEncryptedNotebookStatus endpoint, which fails to enforce publish-access filtering. This allows unauthenticated or publish-mode users to retrieve encrypted notebook identifiers, names, and lock states, thereby enumerating all encrypted notebooks and revealing their current unlock status. The exposure of sensitive notebook metadata and decryption state information could lead to privacy concerns. The CVSS 4.0 base score is 6.9, indicating a medium severity vulnerability. No official patch or remediation guidance is currently provided, and no known exploits are reported in the wild.
Potential Impact
The vulnerability allows unauthorized users, including anonymous readers and publish-mode accounts, to enumerate encrypted notebooks and view their names and unlock states. This leads to information disclosure of sensitive notebook metadata and decryption status, potentially compromising user privacy. There is no indication of direct code execution or data modification impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the getEncryptedNotebookStatus endpoint to trusted users only, if possible, and monitor for unusual access patterns related to notebook enumeration.
CVE-2026-72797: Missing Authorization in siyuan-note siyuan
Description
SiYuan versions before v3.7.4 have an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint. This endpoint returns encrypted notebook identifiers, names, and lock states without proper publish-access filtering. As a result, anonymous users and publish-mode accounts can enumerate all encrypted notebooks and their unlock status, exposing sensitive notebook names and decryption states in memory.
CVSS v4.0
Score 6.9medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-72797 is an information disclosure vulnerability affecting SiYuan note-taking software versions prior to v3.7.4. The vulnerability exists in the getEncryptedNotebookStatus endpoint, which fails to enforce publish-access filtering. This allows unauthenticated or publish-mode users to retrieve encrypted notebook identifiers, names, and lock states, thereby enumerating all encrypted notebooks and revealing their current unlock status. The exposure of sensitive notebook metadata and decryption state information could lead to privacy concerns. The CVSS 4.0 base score is 6.9, indicating a medium severity vulnerability. No official patch or remediation guidance is currently provided, and no known exploits are reported in the wild.
Potential Impact
The vulnerability allows unauthorized users, including anonymous readers and publish-mode accounts, to enumerate encrypted notebooks and view their names and unlock states. This leads to information disclosure of sensitive notebook metadata and decryption status, potentially compromising user privacy. There is no indication of direct code execution or data modification impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the getEncryptedNotebookStatus endpoint to trusted users only, if possible, and monitor for unusual access patterns related to notebook enumeration.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T15:11:03.190Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7cc908bf8831d539077221
Added to database: 08/12/2026, 19:27:04 UTC
Last enriched: 08/12/2026, 19:43:34 UTC
Last updated: 08/12/2026, 22:00:25 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.