Medium severity5.9NVD Advisory· Published Sep 10, 2026
CVE-2026-88897
CVE-2026-88897
Description
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.