CVE-2026-72793: SiYuan before v3.7.4 Information Disclosure via /api/system/getConf
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges.
Security readout for executives and security teams
Plain-English summary
SiYuan before 3.7.4 can reveal secrets through a configuration API to anonymous or publish-reader users. Those secrets may enable account impersonation, session-cookie tampering, and exposure of encrypted-notebook key material. Systems without access-auth codes face the greatest risk because an attacker may gain administrator privileges.
Executive priority
Treat this as an immediate remediation item for reachable SiYuan deployments. Prioritize systems without access-auth codes, externally accessible systems, and environments containing sensitive notebooks. Assume exposed signing or notebook keys may require rotation until investigation establishes otherwise.
Technical view
The /api/system/getConf endpoint fails to mask the session-cookie signing key, encrypted-notebook key material, and an OS username exposed through the pandoc path. A remote attacker may retrieve these values without full authentication. The reported CVSS 4.0 score is 9.2, with low-complexity, network-based access requiring no privileges or user interaction.
Likely exposure
Internet- or network-reachable SiYuan instances running versions earlier than 3.7.4 are potentially exposed. Anonymous access and publish-reader accounts provide attack paths. Instances lacking access-auth codes have the clearest documented route to administrator escalation.
Exploitation context
The bundle reports that this CVE is not in KEV and provides no evidence of active exploitation. Exploitation in the wild is therefore unconfirmed, not ruled out. The low-complexity, unauthenticated network path and high-value disclosed secrets make prompt remediation appropriate.
Researcher notes
The supplied evidence identifies disclosure and subsequent impersonation risk but does not establish real-world exploitation. Validate exposure without retaining disclosed secrets. The described OS username disclosure is secondary; session signing and encrypted-notebook key material drive the principal risk.
Mitigation direction
Upgrade SiYuan to version 3.7.4 or later.
Limit untrusted network access to SiYuan until the upgrade is complete.
Configure access-auth codes where operationally appropriate.
Follow vendor guidance for rotating exposed secrets and invalidating existing sessions.
Assess encrypted notebooks whose key material may have been disclosed.
Validation and detection
Inventory every SiYuan instance and confirm its installed version.
Verify the configuration endpoint no longer returns sensitive fields after upgrading.
Confirm anonymous and publish-reader access cannot retrieve configuration secrets.
Review available logs for suspicious requests to /api/system/getConf.
Confirm access-auth codes are configured on applicable instances.
Verify vendor-recommended secret rotation and session invalidation were completed.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-522: Credential and account abuse lookup
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-522 · source CWE mapping
Insufficiently Protected Credentials
Insufficiently Protected Credentials represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.