What is CVE-2026-68584?
CVE-2026-68584 is an authentication bypass vulnerability in SiYuan versions before v3.7.3, affecting its publish mode. The endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc fail to perform password checks, potentially allowing anonymous attackers to retrieve protected document content. Users should urgently update SiYuan to version 3.7.3 or later.
Azərbaycanca: CVE-2026-68584, SiYuan proqramının 3.7.3 versiyasından əvvəlki versiyalarında publish rejimində autentifikasiya bypass zəifliyidir. 'getHeadingChildrenDOM', 'getHeading*Transaction' və 'getBacklinkDoc' kimi məzmun qaytaran endpoint-lər parol yoxlaması etmir, bu səbəbdən anonim hücumçular qorunan sənədlərə icazəsiz giriş əldə edə bilər. SiYuan istifadəçiləri dərhal v3.7.3 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which mode of the SiYuan application is affected by CVE-2026-68584?
This vulnerability affects the publish mode of the SiYuan application.
What should users do to mitigate this authentication bypass vulnerability?
SiYuan users should urgently update to version 3.7.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.