What is CVE-2026-73046?
SiYuan note-taking application before v3.7.4 has a vulnerability where the CheckAuth middleware lacks rate-limiting on authentication attempts. This flaw in the Basic Authentication branch allows brute force attacks against the workspace access code on nearly the entire /api/* surface. Users should update to version 3.7.4 or later immediately.
Azərbaycanca: SiYuan qeyd dəftəri proqramının v3.7.4 versiyasından əvvəlki versiyalarında CheckAuth middleware-də autentifikasiya cəhdlərinin sayı məhdudlaşdırılmadığı üçün zəiflik var. Bu boşluq API (Application Programming Interface) səthini qoruyan əsas giriş koduna qarşı brute force hücumlarına yol açır. İstifadəçilər dərhal v3.7.4 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
In which component was the CVE-2026-73046 vulnerability discovered in SiYuan?
The vulnerability was discovered in the CheckAuth middleware, where the lack of rate-limiting on authentication attempts created a flaw in the Basic Authentication branch.
Which version should users upgrade to in order to fix the CVE-2026-73046 vulnerability?
Users should update to version 3.7.4 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.