CVE-2026-86192
moderateAuthorization Bypass in SiYuan Publish Exposes Private Attribute-View Data
SiYuan before v3.8.2 fails to properly filter private attribute-view cell values in its getAttributeViewKeys endpoint, an authorization-bypass flaw tracked as CWE-639. A user with publish-reader access can call this endpoint and retrieve hidden KeyValues payloads for rows that are bound to documents they cannot otherwise open. The attacker gains unauthorized read access to private database contents; the 7.1 High CVSS 4.0 score reflects high confidentiality impact with no integrity or availability impact and only low privileges required. Only SiYuan deployments that share content through the Publish feature with external readers are meaningfully affected. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade to SiYuan v3.8.2 or later, which properly filters private attribute-view cell values. Until patched, review and restrict publish-reader access and avoid sharing database rows tied to inaccessible documents, or temporarily disable Publish sharing. Operators should check access logs for publish readers querying the getAttributeViewKeys endpoint.
| SiYuan | all versions before v3.8.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.