CVE-2026-66012: SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP

Published Jul 25, 2026
·
Updated

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp. The attacker can read conf/conf.json to extract accessAuthCode, api.token, and cookieKey in plaintext, write arbitrary files in the workspace, and plant a plugin into data/plugins/ that executes with nodeIntegration:true and no contextIsolation on the next desktop launch, leading to administrator takeover.

Affected Software

1 affected component
SiYuan SiYuan<3.7.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in 3.7.2
  2. Configuration

    Disable anonymous Publish mode by ensuring Conf.Publish.Auth.Enable is set to true (material states vulnerability occurs when Conf.Publish.Auth.Enable=false in anonymous mode).

    SiYuan Publish server Conf.Publish.Auth.Enable = false
  3. Configuration

    Disable the Publish server in anonymous mode by ensuring Conf.Publish.Enable is false when Conf.Publish.Auth.Enable=false (material states unauthenticated access to /mcp is possible with Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false).

    SiYuan Publish server Conf.Publish.Enable = false
  4. Compensating control

    If the Publish reverse proxy must remain enabled, restrict access to the endpoint that proxies /mcp so that unauthenticated internet clients cannot reach /mcp (the material states an unauthenticated attacker can reach /mcp when anonymous Publish mode is enabled).

Event History

Jul 25, 2026
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-66012?

CVE-2026-66012 has a critical severity rating of 10.

2

How do I fix CVE-2026-66012?

To mitigate CVE-2026-66012, update SiYuan to version 3.7.2 or later.

3

What type of vulnerability is CVE-2026-66012?

CVE-2026-66012 is an unauthenticated administrator takeover vulnerability.

4

What components are affected by CVE-2026-66012?

CVE-2026-66012 affects the MCP kernel endpoint and exposes 31 MCP tools.

5

What impact can CVE-2026-66012 have on my system?

CVE-2026-66012 allows an attacker to gain unauthorized admin control over the SiYuan application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203