Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32638

Опубликовано: 18 мар. 2026
Источник: nvd
CVSS3: 2.7
EPSS Низкий

Описание

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API getUsers endpoint in StudioCMS uses the attacker-controlled rank query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin token can request rank=owner and receive owner account records, including IDs, usernames, display names, and email addresses, even though the adjacent getUser endpoint correctly blocks admins from viewing owner users. This is an authorization inconsistency inside the same user-management surface. Version 0.4.4 fixes the issue.

EPSS

Процентиль: 2%
0.00013
Низкий

2.7 Low

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 2.7
github
17 дней назад

StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens

EPSS

Процентиль: 2%
0.00013
Низкий

2.7 Low

CVSS3

Дефекты

CWE-639