CVE-2026-23486
Blinko: Unauthorized User Information Leak
Vexday Risk Score
28Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.7%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
23 Mar 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including usernames, roles, and account creation dates. This issue has been patched in version 1.8.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
blinkospace · blinkoWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →