PatchSiren

YaoApp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM YaoApp CVE published 2026-09-15

CVE-2026-91774

CVE-2026-91774 is a medium-severity vulnerability in the Yao application, where an authenticated but unauthorized user can read full team records by supplying a known team identifier to the GET /user/teams/:id endpoint. This vulnerability allows attackers to access sensitive team data, including names, descriptions, owner information, and settings, without proper authorization or membership verification. [truncated]