CVE-2026-30926Disclosure(b3log / siyuan)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-privilege publish accounts (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API endpoint. The endpoint requires only the model.CheckAuth role, which accepts RoleReader sessions, but it does not enforce stricter checks, such as CheckAdminRole or CheckReadonly. This allows remote authenticated publish users with read-only privileges to append new blocks to existing documents, compromising the integrity of stored notes.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-09: 1Mentions · 2026-03-22: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-22: 103-0903-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-30926 (CVSS 9.1): SiYuan 3.5.9 RoleReader publish esc → modify notebooks via appendHeadingChildren. PKM data integrity risk! https://nvd.nist.gov/vuln/detail/CVE-2026-30926

    Post summary

    CVE-2026-30926 is disclosed with a CVSS score of 9.1, affecting SiYuan 3.5.9 by allowing RoleReader to modify notebooks via appendHeadingChildren, posing a PKM data integrity risk.

    0001061
    374 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30926 SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-p… https://www.cve.org/CVERecord?id=CVE-2026-30926

    Post summary

    Announcement of CVE-2026-30926, a privilege escalation flaw in SiYuan's publish service before version 3.5.10.

    0000071
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more