CVE-2026-86191: SiYuan before v3.8.2 Private Attribute View Key Enumeration

Published Sep 5, 2026
·
Updated

SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.

Affected Software

1 affected component
SiYuan<3.8.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in v3.8.2
  2. Configuration

    Ensure getAttributeViewKeysByID verifies the parent database visibility before returning private attribute view key definitions, to prevent publish readers from enumerating private attribute view keys.

    SiYuan getAttributeViewKeysByID endpoint parent database visibility verification for private attribute view key enumeration = enabled

Event History

Sep 5, 2026
CVE Published
via MITRE·12:09 PM
Data Sourced
via MITRE·12:09 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A publish reader can exploit it. The attacker needs access to the affected SiYuan endpoint but does not need administrative privileges or user interaction.

2

What information may be exposed?

The endpoint can disclose complete private attribute-view key schemas from hidden databases, including sensitive field names and relation definitions.

3

Which deployments are affected?

SiYuan versions before v3.8.2 are affected. Deployments where users have publish-reader access are exposed to this enumeration issue.

4

How can I determine whether sensitive data may already be exposed?

Review access to the getAttributeViewKeysByID endpoint by publish readers and identify hidden databases containing private attribute views. Key-schema retrieval for databases whose parent visibility should have prevented access is indicative of exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203