CVE-2026-69085Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-03: 1Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-14: 108-0308-14
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-031
Patch1
2026-08-141
Disclosure1
Full discourse2 posts
  • SECNORA®@secnorainfosec
    Disclosure

    🚨 CVE-2026-69085: Unauthenticated SQL Injection in SiYuan's “searchDocs" Endpoint An unauthenticated SQL injection flaw allows arbitrary SQL execution in publish mode, earning a maximum CVSS v3.1 score of 10.0. 🔗 Read the full technical analysis: https://secnora.com/blog/cve-2026-69085-siyuan-sql-injection/

    Post summary

    The text announces the discovery of CVE-2026-69085, an unauthenticated SQL injection in SiYuan’s ‘searchDocs’ endpoint that permits arbitrary SQL execution with a maximum CVSS v3.1 score of 10.0.

    0000037
    76 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - SiYuan SQLi via filetree searchDocs keyword (CVE-2026-69085) SiYuan kernel /api/filetree/searchDocs concatenates the user-supplied keyword into SQL without escaping/binding. Reachable with a publish RoleReader token, or unauthenticated when Publish.Auth.Enable=false; stacked SQL on a read-write SQLite handle enables read/modify of DB content across all cleartext notebooks. 👉Affected: http://github.com/siyuan-note/siyuan/kernel < 3.7.3 | Upgrade to 3.7.3

    Post summary

    A critical SQL injection vulnerability (CVE‑2026‑69085) exists in SiYuan’s /api/filetree/searchDocs endpoint, exploitable via unauthenticated or RoleReader tokens, and can be mitigated by upgrading to version 3.7.3.

    0000097
    280 followersView on X

Explore more