CVE-2026-88421

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.

  • Published Sep 25, 2026
  • CVSS 7.5 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

CVE-2026-88421 at the National Vulnerability Database