PT-2026-86417 · Siyuan · Siyuan

·

CVE-2026-86192

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.2
Description Insufficient filtering of private attribute-view cell values occurs in the 'getAttributeViewKeys' endpoint. This allows publish readers to retrieve hidden KeyValues payloads from rows linked to documents they cannot access, leading to unauthorized exposure of private database contents.
Recommendations Update to version 3.8.2 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86192
GHSA-VC7J-5F5P-3X75

Affected Products

Siyuan