CVE-2026-30945 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint a…
High CVSS: 7.1

CVE-2026-30945

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user with editor privileges or above to revoke API tokens belonging to any other user, including admin and owner accounts. The handler accepts tokenID and userID directly from the request payload without verifying token ownership, caller identity, or role hierarchy. This enables targeted denial of service against critical integrations and automations. This vulnerability is fixed in 0.4.0.
Vendor
Studiocms
Product
Studiocms
CWE
CWE-639
Yayın Tarihi
2026-03-10 18:18:54
Güncelleme
2026-03-17 16:17:30
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar