Tag
high
advisory
Blinko Pre-1.8.4 OS Command Injection Vulnerability
2 rules 1 TTP 4 IOCsBlinko versions before 1.8.4 are vulnerable to OS Command Injection (CWE-78), where the MCP server creation function allows specifying arbitrary commands and arguments that are executed when testing the connection, potentially leading to code execution for attackers with high privileges.
cve-2026-23882
command-injection
blinko
2r
1t
4i
critical
advisory
Blinko Privilege Escalation via upsertUser Endpoint
2 rules 1 TTPAn authenticated user can exploit the Blinko upsertUser endpoint to escalate privileges, modify other users' passwords, and achieve account takeover due to missing authentication and verification checks.
privilege-escalation
cve-2026-23480
blinko
2r
1t