Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)

Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)

First seen 26 Jul 2026, 11:03 UTC Feedlyexploit-intel.comwww.incibe.eswww.thehackerwire.comvulners.com+1 88% similarity 78.0

Article Content

Browse articles
ThreatCluster

A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint. This vulnerability exposes 31 MCP tools, including file management capabilities, and enables attackers to read sensitive configuration files and execute arbitrary code with administrative privileges. The flaw is particularly dangerous when the Publish server is enabled in anonymous mode, as it allows attackers to plant malicious plugins that execute on desktop launch. A CVSS base score of 10 has been assigned, indicating critical severity. Currently, there is no evidence of active exploitation or public proof-of-concept available. Users are advised to upgrade to version 3.7.2 or later and review their workspaces for unauthorized files. The vulnerability was first published on July 25, 2026.

Key Points: • CVE-2026-66012 is a critical vulnerability with a CVSS score of 10. • Attackers can exploit the flaw to gain administrative access and execute arbitrary code. • Users must upgrade to SiYuan v3.7.2 or later to mitigate the risk.

ThreatCluster AI

Timeline

2026-07-25
CVE-2026-66012 published
Details of a critical missing authorization vulnerability in SiYuan were disclosed, affecting versions prior to 3.7.2.
Feedly
2026-07-26
INCIBE-CERT issues alert
INCIBE-CERT confirmed the critical nature of CVE-2026-66012, emphasizing the risk of administrator takeover.
www.incibe.es

Community

Browse all →