API Token Exposure in Flextype CMS by Flextype
CVE-2026-88897

8.2HIGH

Key Information:

Vendor

Flextype

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88897?

Flextype CMS versions up to 1.0.0-alpha.3 allow API authentication credentials to be sent via URL query string parameters. This design flaw exposes API tokens to attackers who may access server logs, web proxies, or monitoring tools. Valid token pairs can be harvested, granting unrestricted access to the API endpoints, potentially compromising the security of the entire CMS.

Affected Version(s)

flextype 0 <= 1.0.0-alpha.3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Khafagy
.