Medium severity5.8NVD Advisory· Published Aug 12, 2026· Updated Aug 26, 2026
CVE-2026-72806
CVE-2026-72806
Description
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document rows including titles, block IDs, and column values by calling renderAttributeView without supplying the required password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/siyuan-note/siyuan/kernelGo | < 0.0.0-20260723040913-768427f20f13 | 0.0.0-20260723040913-768427f20f13 |
Affected products
2- Range: <v3.7.4
- ghsa-coordsRange: < 0.0.0-20260723040913-768427f20f13
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-6mcf-g667-w3qvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-72806ghsaADVISORY
- github.com/siyuan-note/siyuan/commit/768427f20f13bbd8dc4effa8aa4e1d09a7741bf4ghsaWEB
- github.com/siyuan-note/siyuan/security/advisories/GHSA-6mcf-g667-w3qvnvdWEB
- www.vulncheck.com/advisories/siyuan-before-authentication-bypass-via-attribute-viewnvdWEB
News mentions
1- Siyuan Note: 22 Vulnerabilities Disclosed Together, Patch Released in v3.7.4Vypr Intelligence · Aug 12, 2026