CVE-2026-88897: Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String

Published Sep 10, 2026
·
Updated

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

Affected Software

1 affected component
Flextype Flextype CMS<=1.0.0-alpha.3

Event History

Sep 10, 2026
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to token theft?

Deployments are exposed when API credentials are sent in REST API URL query parameters and the resulting URLs are recorded by web servers, reverse proxies, or monitoring systems. Anyone who can access those logs may recover valid API token pairs.

2

What access does an attacker need to exploit this?

The attacker does not need prior application privileges, but must be able to view logs or monitoring data that captured REST API request URLs containing the credentials. Recovered token pairs grant full API access.

3

What can be done if an update is not immediately possible?

Avoid placing API authentication credentials in REST API query strings, and restrict access to web server, proxy, and monitoring logs that may contain previously captured URLs. Treat tokens found in such logs as exposed and replace them.

4

How can administrators determine whether credentials may already be exposed?

Review web server, proxy, and monitoring logs for REST API URLs containing API authentication query parameters. Any valid token pair present in those records should be considered compromised because it can grant full API access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203