CVE-2026-88897

Source
https://cve.org/CVERecord?id=CVE-2026-88897
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88897.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88897
Published
2026-09-10T14:46:36Z
Modified
2026-09-12T03:47:22Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
Details

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-598"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88897.json"
}
References

Affected packages

Git / github.com/flextype/flextype

Affected ranges

Type
GIT
Repo
https://github.com/flextype/flextype
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.0.0-alpha.3"
        },
        {
            "fixed": "1.0.0-alpha.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v0.*
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.13
v0.9.14
v0.9.15
v0.9.16
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9
v1.*
v1.0.0-alpha.1
v1.0.0-alpha.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88897.json"