CVE-2026-72794

Summary

siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access.

Affected Software

VendorProductVersion RangeStatus
siyuan-notesiyuan0 < 3.7.4affected
siyuan-notesiyuan3.7.4unaffected

Weaknesses

  • CWE-522: Insufficiently Protected Credentials

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References