CVE-2026-24134

StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authorization (BOLA) vulnerability in the Content Management feature that allows users with the "Visitor" role to access draft content created by Editor/Admin/Owner users. Version 0.2.0 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:studiocms:studiocms:*:*:*:*:*:*:*:*

History

17 Mar 2026, 15:39

Type Values Removed Values Added
CPE cpe:2.3:a:studiocms:studiocms:*:*:*:*:*:*:*:*
First Time Studiocms studiocms
Studiocms
References () https://github.com/withstudiocms/studiocms/commit/efc10bee20db090fdd75463622c30dda390c50ad - () https://github.com/withstudiocms/studiocms/commit/efc10bee20db090fdd75463622c30dda390c50ad - Patch
References () https://github.com/withstudiocms/studiocms/releases/tag/studiocms%400.2.0 - () https://github.com/withstudiocms/studiocms/releases/tag/studiocms%400.2.0 - Release Notes
References () https://github.com/withstudiocms/studiocms/security/advisories/GHSA-8cw6-53m5-4932 - () https://github.com/withstudiocms/studiocms/security/advisories/GHSA-8cw6-53m5-4932 - Exploit, Vendor Advisory
Summary
  • (es) StudioCMS es un sistema de gestión de contenido sin cabeza, nativo de Astro, renderizado en el lado del servidor. Las versiones anteriores a la 0.2.0 contienen una vulnerabilidad de Autorización de Nivel de Objeto Rota (BOLA) en la función de Gestión de Contenido que permite a los usuarios con el rol de 'Visitante' acceder a contenido borrador creado por usuarios Editor/Administrador/Propietario. La versión 0.2.0 corrige el problema.

28 Jan 2026, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 00:15

Updated : 2026-03-17 15:39


NVD link : CVE-2026-24134

Mitre link : CVE-2026-24134

CVE.ORG link : CVE-2026-24134


JSON object : View

Products Affected

studiocms

  • studiocms
CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-862

Missing Authorization