CVE-2026-73045: Siyuan-Note Siyuan

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.

Affected products

Published 2026-08-15. Last modified 2026-08-26.