CVE-2026-72793Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-08-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-13: 1Mentions · 2026-08-14: 1Mentions · 2026-09-05: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-14: 108-1308-1409-05
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-131
Disclosure1
2026-08-141
Patch1
2026-09-051
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 SiYuan Note, Information Disclosure, #CVE-2026-72793 (Critical) -DC-Sep2026-2214 https://dailycve.com/siyuan-note-information-disclosure-cve-2026-72793-critical-dc-sep2026-2214/

    Post summary

    The message alerts that SiYuan Note has a critical information disclosure vulnerability (CVE‑2026‑72793) and provides a link to a daily CVE article, but no further technical or exploit details are given.

    0000045
    234 followersView on X
  • ekofyi@ekofyi
    Patch

    A leaked cookie signing key isn’t “just config exposure.” It can turn session trust into an attacker-controlled boundary. SiYuan users: patch CVE-2026-72793. https://ekofyi.com/blog/siyuan-cve-2026-72793-cookie-signing-key-exposure

    Post summary

    The post announces the discovery of a cookie signing key exposure in SiYuan (CVE‑2026‑72793) and urges users to apply the available patch, linking to a detailed blog post for more information.

    0000063
    170 followersView on X
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 13 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🔑 Config endpoint that hands out its session-signing key — anyone who can reach the port mints a valid session and reads every notebook (SiYuan CVE-2026-72793, CVE-2026-72794) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated SCADA/HMI project read — an anonymous request pulls the plant's screens and the addresses of every device behind them (FUXA CVE-2026-47717) ⚡ Sandbox escape in an AI agent builder — code runs on the host holding every model key and DB credential the flows use, and two of them need no login (Flowise CVE-2026-73483, CVE-2026-73485) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The daily CVE report introduces several new vulnerabilities with technical details, but does not provide PoC, exploit code, active exploitation evidence, or patch information.

    0000045
    5 followersView on X

Explore more