CVE-2026-30926

SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-privilege publish accounts (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API endpoint. The endpoint requires only the model.CheckAuth role, which accepts RoleReader sessions, but it does not enforce stricter checks, such as CheckAdminRole or CheckReadonly. This allows remote authenticated publish users with read-only privileges to append new blocks to existing documents, compromising the integrity of stored notes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*

History

13 Mar 2026, 17:06

Type Values Removed Values Added
Summary
  • (es) SiYuan es un sistema de gestión de conocimiento personal. Anteriormente a la 3.5.10, existe una vulnerabilidad de escalada de privilegios en el servicio de publicación de SiYuan Note que permite a las cuentas de publicación de bajo privilegio (RoleReader) modificar el contenido del cuaderno a través del endpoint de la API /api/block/appendHeadingChildren. El endpoint requiere solo el rol model.CheckAuth, que acepta sesiones de RoleReader, pero no aplica comprobaciones más estrictas, como CheckAdminRole o CheckReadonly. Esto permite a los usuarios de publicación remotos autenticados con privilegios de solo lectura añadir nuevos bloques a documentos existentes, comprometiendo la integridad de las notas almacenadas.
First Time B3log
B3log siyuan
CPE cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
References () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-f9cq-v43p-v523 - () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-f9cq-v43p-v523 - Exploit, Vendor Advisory

10 Mar 2026, 18:18

Type Values Removed Values Added
References () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-f9cq-v43p-v523 - () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-f9cq-v43p-v523 -

10 Mar 2026, 07:44

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 07:44

Updated : 2026-03-13 17:06


NVD link : CVE-2026-30926

Mitre link : CVE-2026-30926

CVE.ORG link : CVE-2026-30926


JSON object : View

Products Affected

b3log

  • siyuan
CWE
CWE-284

Improper Access Control

CWE-862

Missing Authorization