CVE-2026-72794General

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-09-05: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-05: 108-1309-05
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-131
General1
2026-09-051
Disclosure1
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 SiYuan Note Information Disclosure Vulnerability, #CVE-2026-72794 (High) -DC-Sep2026-2216 https://dailycve.com/siyuan-note-information-disclosure-vulnerability-cve-2026-72794-high-dc-sep2026-2216/

    Post summary

    The post announces a new high‑severity information‑disclosure vulnerability (CVE‑2026‑72794) in SiYuan Note, providing only a link for further details.

    0000074
    234 followersView on X
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 13 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🔑 Config endpoint that hands out its session-signing key — anyone who can reach the port mints a valid session and reads every notebook (SiYuan CVE-2026-72793, CVE-2026-72794) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated SCADA/HMI project read — an anonymous request pulls the plant's screens and the addresses of every device behind them (FUXA CVE-2026-47717) ⚡ Sandbox escape in an AI agent builder — code runs on the host holding every model key and DB credential the flows use, and two of them need no login (Flowise CVE-2026-73483, CVE-2026-73485) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The tweet announces new CVEs added to NewScan’s detections, outlining their impact but providing no exploits, patches, or evidence of active exploitation.

    0000045
    5 followersView on X

Explore more