OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-88421

HIGH · CVSS 7.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The BlogPage.get_entries() component in APSL puput versions 1.2.1 to 2.2.0 is vulnerable due to incorrect access controls, enabling unauthenticated attackers to access restricted blog entries through various channels such as the blog index and RSS feed. This exposure can lead to unauthorized information disclosure, potentially compromising sensitive content. Organizations using affected versions should prioritize patching this vulnerability to safeguard their blog data from unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88421
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.