PatchSiren cyber security CVE debrief
CVE-2026-87807 siyuan-note CVE debrief
The CVE-2026-87807 debrief provides details on an authenticated SQL injection vulnerability in the siyuan before v3.8.2. This vulnerability exists in the fullTextSearchBlock endpoint's method=1 query parameter, allowing attackers to inject UNION SELECT statements to read the entire blocks table. This exposure bypasses publish-access controls, potentially leading to the disclosure of all document content and sensitive attributes.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-10-08
Who should care
Defenders and administrators using siyuan versions before v3.8.2 should assess their exposure and prioritize updating to v3.8.2 or later. Those responsible for monitoring and securing access to the fullTextSearchBlock endpoint should implement compensating controls to prevent unauthorized access.
Why it matters
CVE-2026-87807 is an authenticated SQL injection vulnerability in siyuan before v3.8.2, allowing attackers to read the entire blocks table by injecting UNION SELECT statements. Defenders should prioritize verifying exposure, especially for those using affected versions, and implement immediate actions to prevent potential disclosure of document content and sensitive attributes.
- Potential disclosure of all document content and sensitive attributes due to bypassed publish-access controls.
- Possible unauthorized access to sensitive information through injected SQL statements.
- Need for verification of system exposure and impact.
- Priority on updating to v3.8.2 or later to mitigate the vulnerability.
Technical summary
The vulnerability exists in the fullTextSearchBlock endpoint's method=1 query parameter of siyuan versions before v3.8.2. An attacker can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls. This could lead to the exposure of all document content and sensitive attributes. The vulnerability allows attackers to inject malicious SQL statements, potentially resulting in unauthorized access to sensitive information. Defenders should prioritize verifying exposure and assessing the impact on their systems, especially those using siyuan versions before v3.8.2.
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact on their systems, especially those using siyuan versions before v3.8.2. Immediate actions include updating to v3.8.2 or later and implementing compensating controls to monitor and restrict access to the fullTextSearchBlock endpoint.
Recommended defensive actions
- Verify if the system uses siyuan versions before v3.8.2 and update to v3.8.2 or later.
- Implement compensating controls to monitor and restrict access to the fullTextSearchBlock endpoint.
- Review and adjust publish-access controls to prevent unauthorized access to document content and sensitive attributes.
- Conduct a thorough review of system configurations and user access levels to identify potential vulnerabilities.
- Perform a vulnerability assessment to determine the potential impact of the SQL injection vulnerability on the system.
- Develop and implement a patch management process to ensure timely application of security updates.
- Monitor system logs and implement additional security controls to detect and prevent potential attacks.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its existence in siyuan versions before v3.8.2 and the potential for attackers to inject SQL statements. However, specific details on exploitation and victim impact are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87807 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87807
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87807 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87807
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
siyuan before v3.8.2 SQL Injection via fullTextSearchBlock
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87807.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-336w-67gx-gx2h
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-3.8.2-sql-injection-via-fulltextsearchblock
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.