CVE-2026-72789: Siyuan-Note Siyuan

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.

Affected products

Published 2026-08-12. Last modified 2026-08-26.