Missing Authentication in DjangoBlog by liangliangyy
CVE-2026-6577
Key Information:
- Vendor
Liangliangyy
- Status
- Vendor
- CVE Published:
- 19 April 2026
Badges
What is CVE-2026-6577?
A notable vulnerability exists in DjangoBlog by liangliangyy, impacting versions up to 2.1.0.0. This flaw resides within an undisclosed function in the logtracks Endpoint (owntracks/views.py), resulting in a lack of necessary authentication measures. As a result, unauthorized users can potentially exploit this weakness remotely. The exploit for this vulnerability has been made publicly available. Despite early notification attempts, the vendor has not responded to the disclosure.
Affected Version(s)
DjangoBlog 2.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
