CVE ReportsCVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to...
Vulnerability ID: CVE-2026-73607
CVSS Score: 5.8
Published: 2026-10-01
An architectural evaluation of CVE-2026-73607 in the SiYuan personal knowledge management system. This technical advisory details a Missing Authorization (CWE-862) vulnerability in the Go-based backend kernel, specifically within the outline storage API endpoint. Under certain configurations, authenticated low-privilege users can query metadata, heading structures, and block hierarchies of restricted documents.
A Broken Object Level Authorization (BOLA) vulnerability in SiYuan prior to v3.7.4 allows authenticated users to extract document outlines and structural metadata of unauthorized notes via the /api/storage/getOutlineStorage API endpoint.
3.7.4)Remediation Steps:
Read the full report for CVE-2026-73607 on our website for more details including interactive diagrams and full exploit analysis.