What is CVE-2026-73056?
SiYuan kernel versions before 3.7.4 have a vulnerability in the CheckAuth() middleware that does not restrict excessive authentication attempts. The API token is accepted via an Authorization header or a query parameter without proper limitation. Users should upgrade to version 3.7.4 or later.
Azərbaycanca: SiYuan kernel-in 3.7.4-dən əvvəlki versiyalarında CheckAuth() middleware-də həddindən artıq autentifikasiya cəhdini məhdudlaşdırmayan zəiflik var. Bu, API token-i header və ya query parametri ilə təkrar yoxlamalara imkan verir. İstifadəçilərə 3.7.4 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: SiYuan
FAQ2
In which component does CVE-2026-73056 exist in the SiYuan kernel?
The vulnerability exists in the CheckAuth() middleware.
What version should users upgrade to in order to remediate this vulnerability?
Users should upgrade to SiYuan kernel version 3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.