Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval. | |
| Title | SiYuan before 3.7.4 Local Privilege Escalation via elevator.exe | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:36.596Z
Reserved: 2026-08-16T12:59:42.223Z
Link: CVE-2026-74801
No data.
Status : Received
Published: 2026-08-17T11:16:40.323
Modified: 2026-08-17T11:16:40.323
Link: CVE-2026-74801
No data.
OpenCVE Enrichment
No data.