What is CVE-2026-74906?
Versions of SiYuan before v3.7.4 contain an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints. This allows anonymous visitors to discover and read content from documents explicitly marked as forbidden from publish. Upgrading to version 3.7.4 is recommended.
Azərbaycanca: SiYuan v3.7.4 öncəsi versiyalarda, səkkiz publish-mode oxucu endpoint-də yanlış avtorizasiya zəifliyi mövcuddur. Bu, anonim ziyarətçilərə nəşr üçün qadağan edilmiş sənədlərin məzmununu oxumağa imkan verir. Tətbiqi v3.7.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by CVE-2026-74906?
This vulnerability exists in versions of SiYuan before v3.7.4.
What can an anonymous visitor achieve by exploiting CVE-2026-74906?
Anonymous visitors can discover and read content from documents marked as forbidden from publish.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.