CVE-2026-23486

MEDIUM NUCLEI

Blinko: Unauthorized User Information Leak

Title source: cna
STIX 2.1

Description

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including usernames, roles, and account creation dates. This issue has been patched in version 1.8.4.

Nuclei Templates (1)

Blinko <= 1.8.3 - User Information Leak
LOWVERIFIEDby 0x_Akoko
Shodan: http.title:"Blinko"
FOFA: title="Blinko"

Scores

CVSS v3 5.3
EPSS 0.0237
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
blinko/blinko < 1.8.4
blinkospace/blinko < 1.8.4
Published Mar 23, 2026
Tracked Since Mar 24, 2026