CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68586

highCVSS 8.6covered by 1 sourcefirst seen 2026-08-03
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given block (a reference-existence oracle).

⚡ Watch CVE-2026-68586

Get an email if CVE-2026-68586 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-68586

CVE.org record

Embed the live status

CVE-2026-68586 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68586 status](https://www.csirts.com/badge/CVE-2026-68586)](https://www.csirts.com/cve/CVE-2026-68586)