CVE-2026-32767Disclosure(b3log / siyuan)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoint. When the method parameter is set to 2, the endpoint passes user-supplied input directly as a raw SQL statement to the underlying SQLite database without any authorization or read-only checks. This allows any authenticated user — including those with the Reader role — to execute arbitrary SQL statements (SELECT, DELETE, UPDATE, DROP TABLE, etc.) against the application's database. This is inconsistent with the application's own security model: the dedicated SQL endpoint (/api/query/sql) correctly requires both CheckAdminRole and CheckReadonly middleware, but the search endpoint bypasses these controls entirely. This issue has been fixed in version 3.6.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-20)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-17: 1Mentions · 2026-03-20: 3Technical Details · 2026-03-17: 1Technical Details · 2026-03-20: 303-1703-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-171
Disclosure1
2026-03-203
Disclosure3
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32767 SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoi… https://www.cve.org/CVERecord?id=CVE-2026-32767

    Post summary

    The text announces an authorization bypass vulnerability in SiYuan 3.6.0 and earlier, affecting the /api/search/fullTextSearchBlock endpoint.

    00000100
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32767: CRITICAL] SiYuan's versions 3.6.0 & below have a critical authorization bypass flaw in the /api/search/fullTextSearchBlock endpoint, allowing authenticated users to execute unauthorized SQL ...#cve,CVE-2026-32767,#cybersecurity https://cvefind.com/CVE-2026-32767

    Post summary

    The post announces a critical authorization bypass flaw in SiYuan versions 3.6.0 and earlier, enabling authenticated users to run unauthorized SQL via the /api/search/fullTextSearchBlock endpoint.

    0000042
    604 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32767: SiYuan: Authorization Bypass All... Reader role gets full DB access through search API's method=2 parameter - classic authz bypass turning knowledge manage... https://zerodaysignal.com/vulnerability/CVE-2026-32767 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A brief alert announcing an authorization bypass vulnerability (CVE-2026-32767) in SiYuan, highlighting that a simple API query allows full database access, but no PoC, exploit, active exploitation, or patch information is provided.

    0000054
    155 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An authorization bypass in `SiYuan` (CVE-2026-32767) allows arbitrary SQL execution via its search API. Review `SiYuan` deployments for exposure. #SiYuan #SQLi #AuthBypass #Infosec https://www.pulsepatch.io/posts/cve-2026-32767-siyuan-auth-bypass-sql-execution

    Post summary

    The post announces an auth bypass in SiYuan that allows arbitrary SQL execution via its search API, urging administrators to review deployments, but provides no evidence of exploitation, exploits, patches, or PoC details.

    0000038
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more