What is CVE-2026-68586?
SiYuan before v3.7.3 fails to apply publish-access filters to the `/api/ref/getBacklinkDoc` and `/api/ref/getBackmentionDoc` content endpoints, allowing unauthorized access to unpublished document contents. Attackers can read confidential notes; users must immediately update to v3.7.3 or later.
Azərbaycanca: SiYuan qeyd dərc filtrləri `/api/ref/getBacklinkDoc` və `/api/ref/getBackmentionDoc` məzmun endpoint-lərinə tətbiq edilmədiyi üçün dərc edilməmiş sənəd məzmunlarına icazəsiz giriş mümkündür. Bu boşluq vasitəsilə hücumçu məxfi qeydləri oxuya bilər; istifadəçilər dərhal v3.7.3+ versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: SiYuan
FAQ2
What security issue was discovered in SiYuan?
Publish-access filters are not applied to the `/api/ref/getBacklinkDoc` and `/api/ref/getBackmentionDoc` content endpoints, allowing unauthorized access to unpublished document contents.
What action should be taken to protect against this vulnerability?
Users must immediately update to SiYuan v3.7.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.