PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72791 siyuan-note CVE debrief

CVE-2026-72791 is an information disclosure vulnerability in SiYuan v3.7.4-alpha.1 pre-release version. The /api/av/getAttributeViewFieldViews endpoint allows reader-role callers to retrieve the complete database view structure for any database whose avID is supplied, regardless of authorization. This issue was introduced by commit acfc02ee8 and fixed in v3.7.4. Users of SiYuan v3.7.4-alpha.1 pre-release version should apply compensating controls and monitor for potential information disclosure. The CVE record was published on 2026-08-12T20:17:50.550Z and has not been modified since then.

Vendor
siyuan-note
Product
siyuan
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-26
Advisory published
2026-08-12
Advisory updated
2026-08-26

Who should care

Users of SiYuan v3.7.4-alpha.1 pre-release version should apply compensating controls and monitor for potential information disclosure. This includes operators, platform administrators, vulnerability management teams, and security teams who manage or use SiYuan v3.7.4-alpha.1 pre-release version in their environments. Compensating controls and monitoring should be implemented to limit potential damage until a vendor remediation is available. Review and verify affected scope, severity, and vendor guidance to ensure proper prioritization and mitigation of this vulnerability. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Implement compensating controls to limit potential damage and review compensating controls for exposed systems while remediation is scheduled and verified. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Inventory affected systems for the SiYuan v3.7.4-alpha.1 pre-release version. Restrict access to the affected endpoint. Implement compensating controls to limit potential damage. Monitor for potential information disclosure via the /api/av/getAttributeViewFieldViews endpoint. Apply vendor remediation when available. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. This CVE is rated MEDIUM with a CVSS score of 6.9; apply compensating controls and monitor for potential information disclosure. The NVD entry is currently Deferred. The CVE record was published on 2026-08-12T20:17:50.550Z and has not been modified since then. The CVE record was published on 2026-08-12T20:17:50.550Z and has not been modified since then. The NVD entry is currently Deferred. This CVE is rated MEDIUM with a CVSS score of 6.9; apply compensating controls and monitor for potential information disclosure. The NVD entry is currently Deferred. The CVE record was published on 2026-08-12T20:17:50.550Z and has not been

Technical summary

CVE-2026-72791 is an information disclosure vulnerability in SiYuan v3.7.4-alpha.1 pre-release version. The /api/av/getAttributeViewFieldViews endpoint allows reader-role callers to retrieve the complete database view structure for any database whose avID is supplied, regardless of authorization. This issue was introduced by commit acfc02ee8 and fixed in v3.7.4. Affected users should apply compensating controls and monitor for potential information disclosure. The vulnerability allows unauthorized access to database view structures, potentially exposing sensitive information. Users should review and verify affected scope, severity, and vendor guidance to ensure proper prioritization and mitigation of this vulnerability.

Defensive priority

CVE-2026-72791 is rated MEDIUM with a CVSS score of 6.9; apply compensating controls and monitor for potential information disclosure.

Recommended defensive actions

  • Inventory affected systems for the SiYuan v3.7.4-alpha.1 pre-release version.
  • Apply vendor remediation when available.
  • Monitor for potential information disclosure via the /api/av/getAttributeViewFieldViews endpoint.
  • Restrict access to the affected endpoint.
  • Implement compensating controls to limit potential damage.

Evidence notes

The CVE-2026-72791 issue was introduced by commit acfc02ee8 and fixed in v3.7.4. The /api/av/getAttributeViewFieldViews endpoint applies no publish-access filtering, allowing reader-role callers to retrieve the complete database view structure for any database whose avID is supplied, regardless of authorization. Evidence is limited to supplied source corpus and CVE metadata.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72791 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72791

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72791 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72791

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.