CVE-2026-22237

CRITICAL

BLUVOYIX - Unauthenticated Exposure of Sensitive API Documentation

Title source: llm
STIX 2.1

Description

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the APIs exposed by the documentation. Successful exploitation of this vulnerability could allow the attacker to cause damage to the targeted platform by abusing internal functionality.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0042
EPSS Percentile 33.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (1)
blusparkglobal/bluvoyix
Published Jan 14, 2026
Tracked Since Feb 18, 2026