SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85581

HIGH · CVSS 7.5 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to exploit the /api/system/uiproc endpoint in SiYuan versions prior to 3.8.2, where they can submit unlimited attacker-controlled process identifiers. This can lead to a denial of service by exhausting process memory, significantly degrading service availability. Organizations using affected versions should prioritize patching to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85581
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.