What is CVE-2026-74903?
CVE-2026-74903 is an insufficient access control vulnerability in SiYuan before v3.7.4 affecting the /api/lute/spinBlockDOM endpoint. The endpoint uses only CheckAuth middleware instead of CheckAdminRole, allowing authenticated users with RoleEditor or RoleReader roles to perform unauthorized actions. Upgrading to SiYuan v3.7.4 or later is recommended.
Azərbaycanca: CVE-2026-74903 SiYuan proqramının 3.7.4-dən əvvəlki versiyalarında `/api/lute/spinBlockDOM` endpointində yetərsiz giriş nəzarəti zəifliyidir. Bu endpoint yalnız `CheckAuth` ilə qorunur, `CheckAdminRole` yox, bu səbəbdən autentifikasiya olunmuş aşağı səviyyəli istifadəçilər (RoleEditor, RoleReader) icazəsiz əməliyyatlar apara bilər. SiYuan-u v3.7.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which endpoint in SiYuan is affected by CVE-2026-74903?
This vulnerability affects the `/api/lute/spinBlockDOM` endpoint in SiYuan.
Which versions of SiYuan are vulnerable to CVE-2026-74903?
Versions of SiYuan before v3.7.4 are vulnerable to this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.