PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87807 siyuan-note CVE debrief

The CVE-2026-87807 debrief provides details on an authenticated SQL injection vulnerability in the siyuan before v3.8.2. This vulnerability exists in the fullTextSearchBlock endpoint's method=1 query parameter, allowing attackers to inject UNION SELECT statements to read the entire blocks table. This exposure bypasses publish-access controls, potentially leading to the disclosure of all document content and sensitive attributes.

Vendor
siyuan-note
Product
siyuan
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-10-08
Advisory published
2026-09-09
Advisory updated
2026-10-08

Who should care

Defenders and administrators using siyuan versions before v3.8.2 should assess their exposure and prioritize updating to v3.8.2 or later. Those responsible for monitoring and securing access to the fullTextSearchBlock endpoint should implement compensating controls to prevent unauthorized access.

Why it matters

CVE-2026-87807 is an authenticated SQL injection vulnerability in siyuan before v3.8.2, allowing attackers to read the entire blocks table by injecting UNION SELECT statements. Defenders should prioritize verifying exposure, especially for those using affected versions, and implement immediate actions to prevent potential disclosure of document content and sensitive attributes.

  • Potential disclosure of all document content and sensitive attributes due to bypassed publish-access controls.
  • Possible unauthorized access to sensitive information through injected SQL statements.
  • Need for verification of system exposure and impact.
  • Priority on updating to v3.8.2 or later to mitigate the vulnerability.

Technical summary

The vulnerability exists in the fullTextSearchBlock endpoint's method=1 query parameter of siyuan versions before v3.8.2. An attacker can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls. This could lead to the exposure of all document content and sensitive attributes. The vulnerability allows attackers to inject malicious SQL statements, potentially resulting in unauthorized access to sensitive information. Defenders should prioritize verifying exposure and assessing the impact on their systems, especially those using siyuan versions before v3.8.2.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact on their systems, especially those using siyuan versions before v3.8.2. Immediate actions include updating to v3.8.2 or later and implementing compensating controls to monitor and restrict access to the fullTextSearchBlock endpoint.

Recommended defensive actions

  • Verify if the system uses siyuan versions before v3.8.2 and update to v3.8.2 or later.
  • Implement compensating controls to monitor and restrict access to the fullTextSearchBlock endpoint.
  • Review and adjust publish-access controls to prevent unauthorized access to document content and sensitive attributes.
  • Conduct a thorough review of system configurations and user access levels to identify potential vulnerabilities.
  • Perform a vulnerability assessment to determine the potential impact of the SQL injection vulnerability on the system.
  • Develop and implement a patch management process to ensure timely application of security updates.
  • Monitor system logs and implement additional security controls to detect and prevent potential attacks.

Evidence notes

The CVE record and source item provide details on the vulnerability, including its existence in siyuan versions before v3.8.2 and the potential for attackers to inject SQL statements. However, specific details on exploitation and victim impact are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87807 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87807

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87807 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87807

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • siyuan before v3.8.2 SQL Injection via fullTextSearchBlock

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87807.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-336w-67gx-gx2h

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/siyuan-before-3.8.2-sql-injection-via-fulltextsearchblock

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.