CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73056

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-16
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an unauthenticated remote attacker can perform unlimited automated guesses of the API token, particularly when a short or weak custom token has been configured, and upon success gains full RoleAdministrator access enabling arbitrary file operations and SQL queries.

⚡ Watch CVE-2026-73056

Get an email if CVE-2026-73056 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73056

CVE.org record

Embed the live status

CVE-2026-73056 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73056 status](https://www.csirts.com/badge/CVE-2026-73056)](https://www.csirts.com/cve/CVE-2026-73056)