# CVE-2026-54069: SiYuan - Authentication Bypass

> Live exploitation tracking for CVE-2026-54069 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-54069

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **Public exploit available:** Yes
- **Affected products:** SiYuan
- **Weaknesses:** CWE-346 (Origin Validation Error)
- **Tags:** web_application

## Description

SiYuan Note 3.6.5 and prior is vulnerable to authentication bypass. The CheckAuth middleware unconditionally trusted all chrome-extension:// origins, granting RoleAdministrator access without token validation to any request with a spoofed Origin header. Fixed in v3.7.0.

## CrowdSec analysis

[CVE-2026-54069](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-54069) is a newly identified vulnerability, but specific details regarding its nature, affected components, and potential impact have not yet been disclosed. As information becomes available, organizations should monitor official advisories to assess risk and determine appropriate mitigation steps.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-54069 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-54069. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit this vulnerability by sending requests to admin API endpoints such as `/api/system/getConf` with an `Origin` header set to a `chrome-extension://` URL, bypassing authentication and gaining administrator access.

## Timeline

- 2026-06-17: CVE Published. CVE-2026-54069 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-54069 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-54069 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-54069.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-54069) follows observed exploitation activity for CVE-2026-54069. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
