CVE-2026-24134 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authorization (BOLA…
Medium CVSS: 6.5

CVE-2026-24134

StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authorization (BOLA) vulnerability in the Content Management feature that allows users with the "Visitor" role to access draft content created by Editor/Admin/Owner users. Version 0.2.0 patches the issue.
Vendor
Studiocms
Product
Studiocms
CWE
CWE-639
Yayın Tarihi
2026-01-28 00:15:50
Güncelleme
2026-03-17 15:39:51
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar