---
id: CVE-2026-88897
title: >-
  Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials
  through URL query string parameters in REST API routes
summary: >-
  Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials
  through URL query string parameters in REST API routes. Attackers with access
  to web server, proxy, or monitoring logs can recover valid API token pairs
  that grant…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-598
vendor: flextype
product: flextype
affected:
  - flextype <= 1.0.0-alpha.3
published: '2026-09-10'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:17:26.453'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88897'
references:
  - url: 'https://github.com/flextype/flextype'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/flextype/flextype/blob/v1.0.0-alpha.3/src/flextype/core/Endpoints/Api.php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/flextype/flextype/issues/598'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flextype-cms-through-1.0.0-alpha.3-api-token-exposure-via-query-string
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T14:38:00.540606Z'
epss: 0.0056
epssPercentile: 0.44276
ingestedAt: '2026-09-12T23:00:11.404Z'
---

## Overview

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
