CVE-2026-32767 is a critical authorization bypass and SQL injection vulnerability affecting SiYuan personal knowledge management systems versions 3.6.0 and below. This flaw allows any authenticated user, including those with a Reader role, to execute arbitrary SQL commands against the application's database via the /api/search/fullTextSearchBlock endpoint. Rated 9.8 Critical (CVSS:3.1/AV:N/AC:L), it can lead to full compromise of data confidentiality, integrity, and availability by bypassing intended security controls. Although no public exploits or active exploitation are currently reported, the vulnerability is easily exploitable over the network with low attack complexity. Users should upgrade to SiYuan version 3.6.1 or later immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.1CPE matchmatch criteria | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.