Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1476 articles · 105575 vulns · 38/41 feeds (7d)
← Back to list
7.5
CVE-2026-30689EXPLOITED
n/a · n/a

CVE-2026-30689: A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to s

Description

A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.

Affected Products

VendorProductVersions
n/an/an/a

References

  • http://blagadmin.com
  • https://github.com/anjoy8/Blog.Core
  • https://gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40

Related News (1 articles)

Tier C
VulDB9h ago
CVE-2026-30689 | blog.admin up to 8.0 API Interface getinfobytoken access control
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Published3/27/2026
Last enriched8h agov2
Tags
problematic
Trending Score62
Source articles1
Independent1
Info Completeness6/14
Missing: cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 8h ago
v2Tier C8h ago

Updated vendor and product information, changed severity to HIGH, and noted that the vulnerability is actively exploited.

affectedVersionsseverityactivelyExploitedtags
via VulDB
v19h ago

Initial creation