CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69086

highCVSS 7.7covered by 1 sourcefirst seen 2026-08-03
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.

⚡ Watch CVE-2026-69086

Get an email if CVE-2026-69086 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69086

CVE.org record

Embed the live status

CVE-2026-69086 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69086 status](https://www.csirts.com/badge/CVE-2026-69086)](https://www.csirts.com/cve/CVE-2026-69086)