Summary
CVE-2026-73046 is an authentication bypass vulnerability in SiYuan Note affecting the kernel’s CheckAuth() middleware, which guards nearly the entire /api/* surface. Versions before 3.7.4 accept the workspace access code as an HTTP Basic Authentication password without ever consulting the CAPTCHA/lockout gate or incrementing the failure counter used by the normal cookie/session login path, allowing unlimited automated brute-force attempts. Successful exploitation grants an unauthenticated remote attacker full RoleAdministrator access to the kernel; the CVE carries a critical severity rating.
Technical details
- Root cause: The HTTP Basic Auth branch of
CheckAuth()validates the supplied password againstConf.AccessAuthCodebut bypasses the rate-limiting/lockout logic applied to the cookie/session login flow, so failed attempts are never throttled or counted. - Secondary weakness: The access code comparison is not constant-time, which can aid attackers attempting to infer correctness of guesses through timing differences.
- Trigger conditions: The target must be reachable over the network with its
/api/*endpoints exposed and Basic Authentication enabled/accepted. - Attack vector: Network — no authentication or user interaction required; an attacker simply sends repeated HTTP Basic Auth requests against the exposed API.
- Impact: Full administrator takeover of the SiYuan kernel, with complete loss of confidentiality, integrity, and availability of workspace data and functionality.
Affected software
- SiYuan (kernel component,
github.com/siyuan-note/siyuan/kernel) — all versions prior to 3.7.4 - Fixed in version 3.7.4 and later
Severity
- CVSS v3.1 Base Score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 Base Score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade SiYuan to version 3.7.4 or later, where proper CAPTCHA/lockout enforcement and failure-counter tracking are applied to the HTTP Basic Authentication path.
- If unable to patch immediately: Do not expose the SiYuan kernel API directly to the internet; restrict access via a firewall, VPN, or reverse proxy that enforces its own authentication and rate limiting, and rotate the workspace access code after remediation.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Access Authorization - SiYuan,思源笔记 - Raw response body:
exitSiYuan,b3log.org/siyuan

