CVE-2026-88897

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-10 15:17

Updated : 2026-09-15 15:17


NVD link : CVE-2026-88897

Mitre link : CVE-2026-88897

CVE.ORG link : CVE-2026-88897


JSON object : View

Products Affected

No product.

CWE
CWE-598

Use of HTTP Request With Sensitive Query String