Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access. | |
| Title | siyuan before v3.7.4 Session Cookie Key Disclosure via getConf | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T19:36:16.547Z
Reserved: 2026-08-10T15:11:03.190Z
Link: CVE-2026-72794
Updated: 2026-08-12T19:36:11.569Z
Status : Received
Published: 2026-08-12T20:17:50.977
Modified: 2026-08-12T20:17:50.977
Link: CVE-2026-72794
No data.
OpenCVE Enrichment
No data.