CVE-2026-73046Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This allows unauthenticated remote attackers to brute-force the admin access code with unlimited automated requests and obtain full RoleAdministrator access to the kernel. A secondary weakness exists because the access code is compared using a non-constant-time string comparison.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-16: 4Patch / Workaround · 2026-08-16: 2Technical Details · 2026-08-16: 408-16
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Full discourse4 posts
  • HOL@HashgraphOnline
    Patch

    Affected: SiYuan before 3.7.4. Current stable 3.8.0 is the clean upgrade target. Self-hosted operators should patch and inspect proxy logs for repeated Basic Auth failures against /api/*. Full analysis: https://hol.org/blog/cve-2026-73046-siyuan-basic-auth-lockout-bypass

    Post summary

    CVE-2026-73046 causes a Basic Auth lockout bypass in SiYuan versions before 3.7.4; upgrading to 3.8.0 patches the issue, and operators should also check proxy logs for repeated auth failures.

    00020161
    17.5K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    SiYuan < v3.7.4 vulnerable to brute-force on /api/ auth (CVE-2026-73046, CVSS 9.8). Update if deployed. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/SIPG4u7bWf

    Post summary

    CVE‑2026‑73046 is disclosed as affecting SiYuan <3.7.4, enabling brute‑force attacks on /api/auth with a CVSS score of 9.8; the post offers no PoC, exploit, active exploitation details, or patch information.

    0000048
    93 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - SiYuan Unauthenticated Brute-Force to Admin via HTTP Basic Auth (CVE-2026-73046) SiYuan before 3.7.4 fails to rate-limit authentication in its CheckAuth() middleware. The HTTP Basic Auth branch that guards almost the entire /api/* surface accepts the workspace access code as the Basic Auth password but never checks the CAPTCHA/lockout gate or increments the failure counter used by the normal login path. As a result, an unauthenticated remote attacker can brute-force the admin access code with unlimited automated requests and gain full administrator access to the kernel. A non-constant-time comparison of the access code adds a timing side channel. CVSS 9.8. 👉Upgrade SiYuan to 3.7.4, set a long random access code, and don't expose the workspace directly to the internet.

    Post summary

    Older SiYuan versions are vulnerable to unauthenticated brute‑force via HTTP Basic Auth, lacking rate limiting and with a timing side‑channel. The post recommends upgrading to 3.7.4, using a strong access code and not exposing the workspace to the internet, and reports no active exploitation evidence.

    00000101
    292 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73046 SiYuan Authentication Bypass Allows Brute-Forcing Admin Access Code https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73046

    Post summary

    The text announces a new vulnerability (CVE-2026-73046) that permits authentication bypass in SiYuan, enabling brute‑forcing of the admin access code.

    00000110
    4.1K followersView on X

Explore more