CVE-2026-68586 | siyuan-note siyuan up to 3.7.2 API Endpoint getBackmentionDoc privileges management
A vulnerability described as problematic has been identified in siyuan-note siyuan up to 3.7.2. Affected by this vulnerability is an unknown functionality of the file /api/ref/getBacklinkDoc,/api/ref/getBackmentionDoc of the component API Endpoint. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-68586. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More