MEDIUMVulnerability

CVE-2026-72788

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint without authentication.

Properties

severity
MEDIUM
score
5.8
cve_id
CVE-2026-72788
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
published_at
2026-08-12T20:17:50.117
last_modified
2026-08-26T16:56:50.830

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72788 — Ninja Signal Threat Intelligence | Ninja Signal