---
id: CVE-2026-88421
title: >-
  Incorrect access control in the BlogPage.get_entries() component of APSL puput
  v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog
  entries via the blog index, the tag, category, author and date archives, the
  si…
summary: >-
  Incorrect access control in the BlogPage.get_entries() component of APSL puput
  v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog
  entries via the blog index, the tag, category, author and date archives, the
  si…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-284
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:18.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88421'
references:
  - url: 'https://gist.github.com/itsmohitnarayan/736225bd6cd79031a5dfbf56acdb14ae'
    label: cve@mitre.org
  - url: 'https://gist.github.com/itsmohitnarayan/736225bd6cd79031a5dfbf56acdb14ae'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-25T16:45:51.778449Z'
ingestedAt: '2026-09-25T13:08:53.484Z'
---

## Overview

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
