exploit-intel.com
Critical Authentication Bypass Vulnerability in SiYuan (CVE-2026-73046)
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability (CVE-2026-73046) has been identified in SiYuan versions prior to 3.7.4, allowing unauthenticated remote attackers to exploit improper authentication restrictions in the CheckAuth() middleware. The flaw enables brute-force attacks on the admin access code via HTTP Basic Authentication, granting full RoleAdministrator access to the SiYuan kernel and its API. The vulnerability arises from the failure to implement CAPTCHA or lockout mechanisms and the use of non-constant-time string comparison for access code verification. A CVSS score of 9.8 indicates a high severity level, with no public proof-of-concept or evidence of active exploitation reported as of now. Users are advised to upgrade to version 3.7.4 or later and implement network access restrictions and WAFs as interim measures.
Key Points: • CVE-2026-73046 allows brute-force attacks on SiYuan admin access codes. • The vulnerability is critical, with a CVSS score of 9.8, indicating high severity. • Users are urged to upgrade to version 3.7.4 or later and restrict API access.