Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTransport.RoundTrip() in kernel/server/proxy/publish.go). The Publish Service runs on a separate, unauthenticated-by-default listener (default TCP port 6808) and gates named publish-viewer accounts (Conf.Publish.Auth.Accounts) with Basic Auth that has no rate limiting, per-account lockout, or backoff. Unauthenticated remote attackers can submit unlimited password guesses against named accounts to gain access to published notes/notebooks. | |
| Title | SiYuan before 3.7.4 Brute-Force Authentication via Publish Service | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:38.603Z
Reserved: 2026-08-17T10:31:04.592Z
Link: CVE-2026-74868
No data.
Status : Received
Published: 2026-08-17T11:16:41.030
Modified: 2026-08-17T11:16:41.030
Link: CVE-2026-74868
No data.
OpenCVE Enrichment
No data.
-
CWE-307
Improper Restriction of Excessive Authentication Attempts