THREAT OPS › Threat News › Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass
Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass
<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS v1.0.0-alpha.3 contains an authentication validation<br /> vulnerability in the API request-processing functionality. API endpoints<br /> may declare access_token as a required parameter, but the<br /> required-parameter validation only verifies that the corresponding key<br /> exists in the supplied request data.<br /> <br /> A
Original source: https://seclists.org/fulldisclosure/2026/Sep/23