Junglewise Threat Intelligence

CVE-2026-24134: StudioCMS authorization bypass in content management

CVE-2026-24134 · Severity: low · CVSS 3.1 · Published 2026-01-27

Technologies: studiocms (npm). Vendors: StudioCMS, npm.

Executive brief

StudioCMS is a content management system used to create and publish website content with role-based access controls. The vulnerability allows low-privilege "Visitor" users to view unpublished draft content created by editors and administrators by bypassing authorization checks. An attacker could expose confidential business information, unreleased announcements, or sensitive internal communications contained in draft posts.

Technical details

The vulnerability is a Broken Object Level Authorization (BOLA) flaw in the /dashboard/content-management/edit endpoint that validates user authentication but fails to enforce role-based access control (RBAC) or content ownership verification. An authenticated user with the "Visitor" role can directly access draft content by providing the content UUID in the query parameter, bypassing checks that should require Editor/Admin/Owner privileges. The root cause is missing authorization validation on the endpoint. Attack vector is network-based and requires only valid authentication as a low-privilege user; no additional user interaction is needed. An attacker can read any draft content, achieving full information disclosure. The vulnerability was patched in version 0.2.0; affected versions are <=0.1.1.

Affected products

  • StudioCMS StudioCMS <=0.1.1

Timeline

  • 2026-01-27: disclosed
  • 2026-01-27: patched: Fixed in version 0.2.0

References

Related threats