CVE-2026-86192
Last modified
CVE-2026-86192 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86192?
How severe is CVE-2026-86192?
How do I fix CVE-2026-86192?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86187WWBN AVideo generates passwords for external-login accounts …5.9
- CVE-2026-86188AVideo with YPTSocket plugin enabled contains a cross-site s…7.2
- CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notif…9.8
- CVE-2026-8619An unauthenticated denial-of-service vulnerability was ident…7.5
- CVE-2026-86190WWBN AVideo contains a broken access control vulnerability i…9.1
- CVE-2026-86191SiYuan versions before v3.8.2 contain an information disclos…4.3
- CVE-2026-86193grav-plugin-api before 1.0.20 fails to validate group-inheri…8.7
- CVE-2026-86194Grav Form Plugin before 9.1.22 fails to verify page authoriz…6.9
- CVE-2026-86195grav-plugin-api versions before 1.0.20 contain a privilege e…8.7
- CVE-2026-86196Grav API plugin versions before 1.0.20 build password reset …8.7
- CVE-2026-86197Grav before 2.0.20 contains a cross-site scripting vulnerabi…5.1
- CVE-2026-8620IBM Web Server Plug-ins for WebSphere Application Server and…7.5
Are you affected by CVE-2026-86192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
