OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104410

HIGH · CVSS 7.5 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

SiYuan versions prior to 3.8.5 are vulnerable to an information disclosure flaw that enables unauthorized users to access sensitive data from password-protected and publish-disabled database rows through the /api/export/preview endpoint. This vulnerability allows attackers to extract primary-key text and cell values from protected rows by requesting an export preview of a public document. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104410
Severity
HIGH
CVSS
7.5
EPSS
0.38%

Original NVD Description

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.