CVE-2026-86192 - SiYuan before v3.8.2 Information Disclosure via Attribute-View
Brief
CVE ID : CVE-2026-86192
Published : Sept. 5, 2026, 1:18 p. m.
- 7 hours, 27 minutes ago
Description : SiYuan versions before v3.
- 2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
Severity: 7.1
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
