CVE-2026-30689

In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. NOTE: Blog.Admin is related front-end code that does not offer an API service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anjoy8:blog.admin:8.0:*:*:*:*:*:*:*

History

02 Jul 2026, 20:17

Type Values Removed Values Added
References
  • {'url': 'http://blagadmin.com', 'tags': ['Broken Link'], 'source': 'cve@mitre.org'}
  • {'url': 'https://github.com/anjoy8/Blog.Core', 'tags': ['Product'], 'source': 'cve@mitre.org'}
  • () https://github.com/anjoy8/Blog.Core/blob/bcb4d17ccc71e206a0c2ff663faf4b399e19f687/Blog.Core.Api/Controllers/UserController.cs#L139-L140 -
CWE CWE-863
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 4.3
Summary (en) A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. (en) In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. NOTE: Blog.Admin is related front-end code that does not offer an API service.

02 Apr 2026, 19:57

Type Values Removed Values Added
First Time Anjoy8 blog.admin
Anjoy8
References () http://blagadmin.com - () http://blagadmin.com - Broken Link
References () https://gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40 - () https://gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40 - Exploit, Third Party Advisory
References () https://github.com/anjoy8/Blog.Core - () https://github.com/anjoy8/Blog.Core - Product
CPE cpe:2.3:a:anjoy8:blog.admin:8.0:*:*:*:*:*:*:*

27 Mar 2026, 21:17

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 15:16

Updated : 2026-07-02 20:17


NVD link : CVE-2026-30689

Mitre link : CVE-2026-30689

CVE.ORG link : CVE-2026-30689


JSON object : View

Products Affected

anjoy8

  • blog.admin
CWE
CWE-863

Incorrect Authorization

CWE-284

Improper Access Control