Data Exposure Vulnerability in Blinko by Blinko Space
CVE-2026-23486

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
23 March 2026

What is CVE-2026-23486?

Blinko, an AI-driven card note-taking application, has a security vulnerability that allows unauthorized access to sensitive user information. Before version 1.8.4, this application featured a publicly accessible endpoint that exposed critical data such as usernames, user roles, and account creation timestamps. The exposure of such information could lead to various security risks including identity theft and unauthorized account access. This vulnerability has been addressed in version 1.8.4, which includes updates to secure all user data.

Affected Version(s)

blinko < 1.8.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.