What is CVE-2026-74904?
CVE-2026-74904 is an authorization vulnerability in SiYuan before v3.7.4, affecting 17 block metadata/content endpoints in kernel/api/block.go via handlers like getRefText. It allows anonymous actors to bypass publish-access filtering and access sensitive block data with only basic authentication. Users must upgrade to v3.7.4 or later immediately.
Azərbaycanca: CVE-2026-74904, SiYuan qeydiyyat proqramının 3.7.4 versiyasından əvvəlki versiyalarında 17 blok metadata/content endpointində avtorizasiya çatışmazlığıdır. Bu zəiflik anonim istifadəçilərə yalnız sadə autentifikasiyadan keçərək həssas blok məlumatlarına müdaxilə etməyə imkan verir. İstifadəçilər dərhal proqramı 3.7.4 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by CVE-2026-74904?
This vulnerability affects SiYuan versions prior to v3.7.4.
What should I do to protect against CVE-2026-74904?
Users must upgrade to v3.7.4 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.