45
30
30
30
45
45
45
30
30
30
30
30
30
30
30
30
30
45
45
30
30
30
30
Code42 Incydr and Okta Identity Cloud integration improve organizations’ data security risk postures
30
30
Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass
Flextype CMS v1.0.0-alpha.3 API endpoints accept a NULL access_token because isset() validation lets requests bypass authentication.
Flextype CMS v1.0.0-alpha.3 API endpoints can declare access_token as a required parameter, but required-parameter validation only verifies the key exists in the request data. Authentication is then verified inside an isset($data['access_token']) condition, which in PHP treats a NULL value as absent. This allows requests supplying a NULL access_token to bypass authentication on affected endpoints. The flaw was disclosed on the Full Disclosure mailing list on September 3, 2026.
28
30
30
30
30
30
45
30
30
30
45
30
45
30
30