SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85624

MEDIUM · CVSS 6.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Blinko 1.8.7 is vulnerable to a cross-user private note disclosure due to a lack of ownership verification in the noteReferenceList procedure, allowing authenticated attackers to enumerate note IDs and access the full content of other users' private notes, including attachments and tags. This vulnerability poses a risk of unauthorized information disclosure, making it critical for organizations using this version to prioritize remediation. Users handling sensitive information in their note-taking applications should take immediate action to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85624
Severity
MEDIUM
CVSS
6.5
EPSS
0.39%

Original NVD Description

Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags.