CVE-2026-86191
Last modified
CVE-2026-86191 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86191?
How severe is CVE-2026-86191?
How do I fix CVE-2026-86191?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86186AVideo API fails to enforce rate limits when clients send a …6.5
- CVE-2026-86187WWBN AVideo generates passwords for external-login accounts …5.9
- CVE-2026-86188AVideo with YPTSocket plugin enabled contains a cross-site s…7.2
- CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notif…9.8
- CVE-2026-8619An unauthenticated denial-of-service vulnerability was ident…7.5
- CVE-2026-86190WWBN AVideo contains a broken access control vulnerability i…9.1
- CVE-2026-86192SiYuan versions before v3.8.2 fail to properly filter privat…6.5
- CVE-2026-86193grav-plugin-api before 1.0.20 fails to validate group-inheri…8.7
- CVE-2026-86194Grav Form Plugin before 9.1.22 fails to verify page authoriz…6.9
- CVE-2026-86195grav-plugin-api versions before 1.0.20 contain a privilege e…8.7
- CVE-2026-86196Grav API plugin versions before 1.0.20 build password reset …8.7
- CVE-2026-86197Grav before 2.0.20 contains a cross-site scripting vulnerabi…5.1
Are you affected by CVE-2026-86191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
