Blinko <= 1.8.4 contains an information disclosure caused by a publicly accessible endpoint exposing user information including usernames, roles, and account creation dates, letting remote attackers access sensitive user data, exploit requires no special privileges.
id: CVE-2026-23486
info:
name: Blinko <= 1.8.3 - User Information Leak
author: 0x_Akoko
sever
...