CVE-2026-86192 UNKNOWN

CVE-2026-86192

Published: 2026-09-05

Description

SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…