Junglewise Threat Intelligence

CVE-2026-32106: StudioCMS REST API missing rank check in user creation

CVE-2026-32106 · Severity: low · CVSS 3.1 · Published 2026-03-12

Technologies: studiocms (npm). Vendors: StudioCMS, npm.

Executive brief

StudioCMS is a content management system with a REST API for managing users and permissions. An admin account can exploit a flaw in the REST API's authorization checks to create additional admin accounts at the same privilege level, enabling persistence and privilege proliferation even if their password is reset or API token is revoked. The vulnerability requires existing admin access, limiting its impact but creating an avenue for account takeover.

Technical details

The REST API createUser endpoint in secure.ts only checks for owner rank creation attempts but lacks the proper rank comparison logic present in the Dashboard API. While the Dashboard API correctly uses indexOf to prevent creating users at or above the caller's own rank, the REST API uses string-based checks that only block owner rank and allow admins to create peer admin accounts. An attacker with a compromised admin API token can POST to /studiocms_api/rest/v1/secure/users with rank set to "admin" to create additional administrative accounts. The vulnerability is classified as improper privilege management (CWE-269) and requires high privileges (admin access) but is exploitable over the network with no user interaction required. A patch has been released in version 0.4.3 that aligns the REST API checks with the correct Dashboard API logic.

Affected products

  • StudioCMS StudioCMS <=0.4.2

Timeline

  • 2026-03-12: disclosed: GHSA-wj56-g96r-673q published
  • 2026-03-12: patched: Fix released in version 0.4.3

References

Related threats