Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40259

26
FAUCET Score

OVERVIEW CVE-2026-40259 is an authorization bypass vulnerability affecting SiYuan, an open-source personal knowledge management system, in versions 3.6.3 and below. The flaw exists in the /api/av/removeUnusedAttributeView endpoint, which improperly validates user permissions before deleting attribute view files. An authenticated user with minimal read-level access can exploit publicly exposed data identifiers to permanently delete arbitrary attribute view definitions from the workspace, causing database views and content rendering to fail until manual restoration occurs. SEVERITY The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring only low complexity and valid authentication credentials. While confidentiality impact is none, the integrity and availability impacts are rated high, as attackers can permanently destroy critical workspace components. The attack requires no user interaction and affects the entire system equally regardless of scope. Exploitation requires authenticated access with publish-service RoleReader privileges, which is a relatively low barrier to entry. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog, and exploit code availability through public channels is not documented. Community attention is minimal, though the issue was addressed in version 3.6.4. The EPSS score of 0.00026 indicates this remains a low-probability exploitation target compared to other known vulnerabilities, suggesting limited real-world threat activity at this time.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.4CPE matchmatch criteria
cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 20th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/siyuan-note/siyuan/kernelFixed in: 0.0.0-20260407035653-2f416e5253f1

Vendor Advisories (1)

goGHSA-7m5h-w69j-qggghigh

SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`

Apr 10, 2026

References

github.com / siyuan-note/siyuan/releases/tag/v3.6.4
Release Notes
github.com / siyuan-note/siyuan/security/advisories/GHSA-7m5h-w69j-qggg
ExploitThird Party Advisory