Security Advisory

CVE-2026-86192

6.5
MEDIUM

Vulnerability Description

SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
Published Date September 5, 2026
Official Source NIST NVD Advisory