CVE-2026-51937
the affected product
An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component
- CVSS
- 7.5
- EPSS
- 0.35% 27.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08