What is CVE-2026-74868?
SiYuan versions before 3.7.4 have an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation, accessible on TCP port 6808. This allows remote attackers to perform unlimited authentication attempts. Users should update to version 3.7.4 or later immediately.
Azərbaycanca: SiYuan proqramının 3.7.4-dən əvvəlki versiyalarında Publish Service-in Basic Auth mexanizmində məhdudlaşdırılmamış brute-force zəifliyi aşkarlanıb. Bu boşluq, TCP 6808 portunda işləyən xidmətin autentifikasiya cəhdlərini saymaması səbəbindən uzaqdan şifrə sındırmağa imkan verir. İstifadəçilərə dərhal 3.7.4 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: SiYuan
FAQ2
Which SiYuan versions are affected by CVE-2026-74868?
All SiYuan versions before 3.7.4 are affected by this vulnerability.
How can I protect my system from CVE-2026-74868?
You should immediately update SiYuan to version 3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.