CVE-2026-72798Patch

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block type.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-09-05: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-05: 108-1309-05
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-131
Patch1
2026-09-051
Disclosure1
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Anytype, Publish Filter Row-Access Bypass, #CVE-2026-72798 (Medium) -DC-Sep2026-2217 https://dailycve.com/anytype-publish-filter-row-access-bypass-cve-2026-72798-medium-dc-sep2026-2217/

    Post summary

    A new CVE‐2026‐72798 vulnerability in Anytype—a publish filter row‑access bypass—is disclosed with medium severity on DailyCVE. No PoC or exploit details are provided.

    0000054
    234 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-72798 - High severity info disclosure in SiYuan. Unpatched v3.7.4 lets anonymous readers access hidden database content via related-database bypass. CVSS 8.6. Update immediately. #CVE #SiYuan #infosec https://www.valtersit.com/cve/CVE-2026-72798/ #infosec #CVE #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta

    Post summary

    High‑severity info disclosure in SiYuan v3.7.4 allows anonymous readers to access hidden database content via a related‑database bypass; users are urged to apply updates immediately.

    0000048
    1.0K followersView on X

Explore more