Cross-User Private Note Disclosure Vulnerability in Blinko by BlinkoSpace
CVE-2026-85624
7.1HIGH
What is CVE-2026-85624?
Blinko version 1.8.7 is susceptible to a cross-user private note disclosure vulnerability due to the lack of ownership verification in the noteReferenceList procedure. This flaw allows authenticated attackers to exploit the vulnerability by enumerating sequential note IDs, potentially gaining access to private notes of other users, including their attachments and tags. The absence of proper access controls significantly compromises user privacy and data integrity, making it crucial for users to update to a patched version to safeguard sensitive information.
Affected Version(s)
blinko 0 <= 1.8.8
