A critical missing authorization vulnerability (CVE-2026-66012) affects SiYuan versions before v3.7.2. The POST /mcp kernel endpoint lacks role-based access controls, permitting unrestricted access to 31 MCP tools including file management capabilities (list/read/write/delete/rename/copy). When the Publish server operates in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the reverse proxy attaches an anonymous RoleReader JWT to requests, enabling remote unauthenticated attackers to exploit the flaw. Successful exploitation could result in full workspace compromise through arbitrary file manipulation. The vulnerability carries a CVSS score of 10.0 (Critical severity). All SiYuan users are advised to upgrade to v3.7.2 immediately to mitigate this risk. No workarounds are available for versions prior to the fix.