Junglewise Threat Intelligence

CVE-2026-88421: Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to vie

CVE-2026-88421 · Severity: high · CVSS 7.5 · Published 2026-09-25

Executive brief

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.

References