CVE-2026-85624
Received Received - Intake

Blinko Private Note Disclosure via Note ID Enumeration

Vulnerability report for CVE-2026-85624, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
blinkospace blinko to 1.8.8 (inc)
blinko blinko 1.8.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-85624 is a cross-user private note disclosure vulnerability in Blinko 1.8.7. The noteReferenceList procedure fails to verify ownership of note identifiers, allowing authenticated attackers to sequentially enumerate note IDs and access other users' private notes, including attachments and tags.

Detection Guidance

To detect this vulnerability, check if your Blinko instance is running version 1.8.7 or below. Authenticated users can test for the flaw by attempting to access notes via sequential ID enumeration or by using the noteReferenceList procedure with another user's note IDs. Monitor logs for unauthorized note access attempts or unusual note ID queries.

Impact Analysis

This vulnerability allows attackers to read private notes, attachments, and tags of other users. If you use Blinko, an attacker could access sensitive information you intended to keep private, even if your notes are marked as private.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive personal data, violating GDPR's data protection principles and HIPAA's privacy rules. Organizations using Blinko may face compliance breaches, legal penalties, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Immediately upgrade Blinko to version 1.8.8 or later. Review and restrict access to the noteReferenceList procedure to ensure proper authorization checks. Audit all note access logs for signs of exploitation. If self-hosted, apply patches from the official repository and disable the vulnerable endpoints if necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85624. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart