CVE-2026-66012: SiYuan Missing Authorization in MCP Kernel Endpoint
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint that, when Publish server is enabled in anonymous mode, allows remote unauthenticated attackers to read sensitive configuration files, write arbitrary files, and plant malicious plugins leading to administrator takeover.
Disclosed 25 July 2026 · Record updated 13 September 2026
Impact
Remote unauthenticated attacker can read sensitive credentials from conf/conf.json, write arbitrary files to workspace, and execute malicious code with administrator privileges via plugin installation.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-66012
