ADK Cyber[verified]@ADKCyberDisclosure
CVE‑2026‑73046 is disclosed as affecting SiYuan <3.7.4, enabling brute‑force attacks on /api/auth with a CVSS score of 9.8; the post offers no PoC, exploit, active exploitation details, or patch information.
Upwind Security MDR[verified]@UpwindMDRPatch
Older SiYuan versions are vulnerable to unauthenticated brute‑force via HTTP Basic Auth, lacking rate limiting and with a timing side‑channel. The post recommends upgrading to 3.7.4, using a strong access code and not exposing the workspace to the internet, and reports no active exploitation evidence.
HOL@HashgraphOnlinePatch
CVE-2026-73046 causes a Basic Auth lockout bypass in SiYuan versions before 3.7.4; upgrading to 3.8.0 patches the issue, and operators should also check proxy logs for repeated auth failures.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces a new vulnerability (CVE-2026-73046) that permits authentication bypass in SiYuan, enabling brute‑forcing of the admin access code.