DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-73607: CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure

CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure

Vulnerability ID: CVE-2026-73607
CVSS Score: 5.8
Published: 2026-10-01

An architectural evaluation of CVE-2026-73607 in the SiYuan personal knowledge management system. This technical advisory details a Missing Authorization (CWE-862) vulnerability in the Go-based backend kernel, specifically within the outline storage API endpoint. Under certain configurations, authenticated low-privilege users can query metadata, heading structures, and block hierarchies of restricted documents.

TL;DR

A Broken Object Level Authorization (BOLA) vulnerability in SiYuan prior to v3.7.4 allows authenticated users to extract document outlines and structural metadata of unauthorized notes via the /api/storage/getOutlineStorage API endpoint.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862 (Missing Authorization)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 / v4.0: 5.8 (Medium) / 6.9 (Medium)
  • EPSS Score: 0.00325 (Percentile: 23.20%)
  • Impact: Information Disclosure (Confidentiality: Low)
  • Exploit Status: PoC Available / No Active Exploitation
  • KEV Status: Not Listed

Affected Systems

  • SiYuan Personal Knowledge Management System
  • SiYuan: >= 0, < 3.7.4 (Fixed in: 3.7.4)

Mitigation Strategies

  • Upgrade SiYuan to v3.7.4 or later
  • Implement network-level segmentation to restrict API access
  • Restrict user creation and guest access on server-mode instances

Remediation Steps:

  1. Verify the currently running version of the SiYuan kernel by inspecting the application logs or interface settings.
  2. Download the latest stable release (v3.8.0 or newer) from the official repository.
  3. Replace the old executable or container image with the updated version.
  4. Restart the SiYuan service and monitor authentication logs for standard API requests.

References


Read the full report for CVE-2026-73607 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)