CVE-2026-23486 affects Blinko, an AI-powered card note-taking project, in versions prior to 1.8.4, where a publicly accessible endpoint exposes all user information including usernames, roles, and account creation dates. Rated CVSS 5.3 MEDIUM, this vulnerability allows unauthenticated attackers to easily access sensitive user data over the network with low attack complexity, resulting in a limited loss of confidentiality. The issue has been patched in version 1.8.4. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.4CPE matchmatch criteria | cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.