Skip to content

CVE-2026-66012

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
July 25, 2026
Last Seen
July 26, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint. This vulnerability exposes 31 MCP tools, including file management capabilities,...

Public Exploits

Checking GitHub for proof-of-concept code…

Related Articles (4)