CVE-2026-86192

SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 13:18

Updated : 2026-09-10 16:18


NVD link : CVE-2026-86192

Mitre link : CVE-2026-86192

CVE.ORG link : CVE-2026-86192


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key