MEDIUMVulnerability

CVE-2026-85624

Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-85624
signal_observed_at
2026-09-16T13:31:01+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-04T15:17:42.737
last_modified
2026-09-10T15:53:23.707

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85624 — Ninja Signal Threat Intelligence | Ninja Signal