What is CVE-2026-73049?
CVE-2026-73049 is an information disclosure vulnerability in the getAttributeViewBacklinks endpoint of SiYuan versions before v3.7.4, where a forbidden access list is incorrectly consulted instead of the visibility list when filtering backlinks. Anonymous readers can supply a publicly visible database row identifier to discover confidential information. Affected users should immediately update SiYuan to version v3.7.4 or later.
Azərbaycanca: CVE-2026-73049, SiYuan-ın v3.7.4-dən əvvəlki versiyalarında getAttributeViewBacklinks endpoint-də informasiya sızması zəifliyidir. Bu zəiflik anonim oxuculara ictimai verilənlər bazası sətir identifikatoru təqdim edərək məxfi məlumatları kəşf etməyə imkan verir. Təsirə məruz qalan istifadəçilər dərhal SiYuan-ı v3.7.4 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What product is affected by CVE-2026-73049 and how is the vulnerability exploited?
This vulnerability affects SiYuan versions before v3.7.4. Anonymous readers can discover confidential information by supplying a publicly visible database row identifier via the getAttributeViewBacklinks endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.