CVE-2026-66012 is a critical missing authorization vulnerability in SiYuan before version 3.7.2 affecting the POST /mcp kernel endpoint. The endpoint is protected only by a general authentication check and does not enforce administrator-role restrictions or read-only controls. As a result, authenticated access at an insufficient privilege level can still reach sensitive MCP functionality. The exposed MCP surface includes 31 tools, notably a file-management capability that permits listing, reading, writing, deleting, renaming, and copying content across the entire workspace. When the Publish server is enabled in anonymous mode, the reverse-proxy path supplies an anonymous reader token to proxied requests, allowing a remote unauthenticated attacker to access /mcp despite the lack of proper authorization checks. Through this access, an attacker can read plaintext secrets from configuration data, modify workspace contents, and place a malicious plugin in the plugins directory. Because the planted plugin executes on the next desktop launch with Node integration enabled and without context isolation, the flaw can be escalated from unauthorized file access to arbitrary code execution and full administrator compromise of the affected environment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.