Overview
- Bluspark Global
- BLUVOYIX
Description
Statistics
- 1 Post
Fediverse
HOLY COW, BATMAN:
Complete takeover of a high-value target system, without cracking skills, nor any complex chained attacks:
CVE-2026-22236: APIs did not check for a valid authorization token. As a result, all APIs were unauthenticated.
and
CVE-2026-22240: Plaintext passwords. There were 3 APIs that could be used to retrieve the plaintext passwords of all accounts, including admins.
Overview
- Bluspark Global
- BLUVOYIX
Description
Statistics
- 1 Post
Fediverse
HOLY COW, BATMAN:
Complete takeover of a high-value target system, without cracking skills, nor any complex chained attacks:
CVE-2026-22236: APIs did not check for a valid authorization token. As a result, all APIs were unauthenticated.
and
CVE-2026-22240: Plaintext passwords. There were 3 APIs that could be used to retrieve the plaintext passwords of all accounts, including admins.