Critical Authentication Bypass Vulnerability in SiYuan (CVE-2026-73046)

Critical Authentication Bypass Vulnerability in SiYuan (CVE-2026-73046)

First seen 16 Aug 2026, 21:49 UTC Feedlyexploit-intel.comwww.incibe.escvefeed.io 90% similarity 76.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-73046) has been identified in SiYuan versions prior to 3.7.4, allowing unauthenticated remote attackers to exploit improper authentication restrictions in the CheckAuth() middleware. The flaw enables brute-force attacks on the admin access code via HTTP Basic Authentication, granting full RoleAdministrator access to the SiYuan kernel and its API. The vulnerability arises from the failure to implement CAPTCHA or lockout mechanisms and the use of non-constant-time string comparison for access code verification. A CVSS score of 9.8 indicates a high severity level, with no public proof-of-concept or evidence of active exploitation reported as of now. Users are advised to upgrade to version 3.7.4 or later and implement network access restrictions and WAFs as interim measures.

Key Points: • CVE-2026-73046 allows brute-force attacks on SiYuan admin access codes. • The vulnerability is critical, with a CVSS score of 9.8, indicating high severity. • Users are urged to upgrade to version 3.7.4 or later and restrict API access.

ThreatCluster AI How this analysis works

Timeline

2026-08-15
CVE-2026-73046 published
CVE-2026-73046 details were published, revealing critical authentication bypass vulnerabilities in SiYuan.
cvefeed.io
2026-08-16
Exploitation potential assessed
Security assessments indicate potential for brute-force attacks on the SiYuan API due to the vulnerability.
Feedly
2026-08-16
Recommendations issued
Experts recommend upgrading to SiYuan version 3.7.4 and implementing network access controls as immediate measures.
exploit-intel.com

Community

Browse all →

Tracked Entities in This Story