← Back to Research Blog
CRITICAL CVE-2026-66012

Critical Zero-Day Vulnerability in SiYuan Exposes Sensitive Data and Enables Remote Code Execution

10.0
CRITICAL
siyuan
2026-08-14

Overview

CVE-2026-66012, a CVSS-10.0 vulnerability in SiYuan, allows unauthenticated attackers to bypass authorization and perform arbitrary file operations, including data exfiltration and plugin execution. This flaw poses severe risks to organizations using SiYuan, particularly Defense Industrial Base (DIB) and enterprise environments.


Technical Analysis

The vulnerability stems from a missing admin-role enforcement in the POST /mcp endpoint, accessible via the Publish server in anonymous mode. When Conf.Publish.Auth.Enable is false, the reverse proxy appends a RoleReader JWT to unauthenticated requests. This enables attackers to read/write/delete workspace files, extract plaintext credentials (accessAuthCode, api.token, cookieKey), and deploy malicious plugins with node-level execution privileges. Exploitation requires no credentials and can be triggered via simple HTTP requests to the /mcp endpoint.

Enterprise & DIB Impact

DIB and enterprises leveraging SiYuan for sensitive documentation or collaboration face immediate risks of intellectual property theft, sabotage, or persistent access. Attackers could alter mission-critical data, inject malicious code into workflows, or disrupt operations by tampering with published content or internal tools.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512