High severity7.5NVD Advisory· Published Mar 27, 2026· Updated Apr 2, 2026
CVE-2026-30689
CVE-2026-30689
Description
A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.
Affected products
1- cpe:2.3:a:anjoy8:blog.admin:8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40nvdExploitThird Party Advisory
- blagadmin.comnvdBroken Link
News mentions
0No linked articles in our index yet.