CVE-2026-88897 PUBLISHED

Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String

Assigner: VulnCheck
Reserved: 10.09.2026 Published: 10.09.2026 Updated: 10.09.2026

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor flextype
Product flextype
Versions Default: unaffected
  • affected from 0 to 1.0.0-alpha.3 (incl.)

Credits

  • Ali Khafagy finder

References

Problem Types

  • Use of GET Request Method With Sensitive Query Strings CWE