Junglewise Threat Intelligence

CVE-2026-19975: Azuriom CMS time-of-check time-of-use in money transfer

CVE-2026-19975 · Severity: low · CVSS 3.1 · Published 2026-08-17

Executive brief

Azuriom CMS is a content management system used to host game servers and manage community websites. A timing weakness in the money transfer feature allows attackers to exploit a race condition and perform unauthorized fund transfers. This could result in financial loss or account compromise for users managing game server economies.

Technical details

A time-of-check time-of-use (TOCTOU) vulnerability exists in the transferMoney function of ProfileController.php in the Money Transfer Handler component. The vulnerability allows a time-window between validation and execution of money transfer operations, enabling attackers to manipulate fund transfers. Attack requires remote network access and high complexity exploitation techniques. The vulnerability has been patched in version 1.2.13 via commit ae5596a9548e010a8a79838806eff60ef9554539. The vendor was notified prior to public disclosure.

Affected products

  • Azuriom Azuriom CMS up to 1.2.12

Timeline

  • 2026-08-17: disclosed
  • 2026-06-29: patched: Patch commit ae5596a9548e010a8a79838806eff60ef9554539; fix released in version 1.2.13

References