OVERVIEW CVE-2026-40259 is an authorization bypass vulnerability affecting SiYuan, an open-source personal knowledge management system, in versions 3.6.3 and below. The flaw exists in the /api/av/removeUnusedAttributeView endpoint, which improperly validates user permissions before deleting attribute view files. An authenticated user with minimal read-level access can exploit publicly exposed data identifiers to permanently delete arbitrary attribute view definitions from the workspace, causing database views and content rendering to fail until manual restoration occurs. SEVERITY The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring only low complexity and valid authentication credentials. While confidentiality impact is none, the integrity and availability impacts are rated high, as attackers can permanently destroy critical workspace components. The attack requires no user interaction and affects the entire system equally regardless of scope. Exploitation requires authenticated access with publish-service RoleReader privileges, which is a relatively low barrier to entry. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog, and exploit code availability through public channels is not documented. Community attention is minimal, though the issue was addressed in version 3.6.4. The EPSS score of 0.00026 indicates this remains a low-probability exploitation target compared to other known vulnerabilities, suggesting limited real-world threat activity at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.4CPE matchmatch criteria | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.