Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 15:17
Updated : 2026-09-10 15:53
NVD link : CVE-2026-85624
Mitre link : CVE-2026-85624
CVE.ORG link : CVE-2026-85624
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
