Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8cw6-53m5-4932 | StudioCMS has Authorization Bypass Through User-Controlled Key |
Tue, 17 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Studiocms
Studiocms studiocms |
|
| CPEs | cpe:2.3:a:studiocms:studiocms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Studiocms
Studiocms studiocms |
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Withstudiocms
Withstudiocms studiocms |
|
| Vendors & Products |
Withstudiocms
Withstudiocms studiocms |
Tue, 27 Jan 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authorization (BOLA) vulnerability in the Content Management feature that allows users with the "Visitor" role to access draft content created by Editor/Admin/Owner users. Version 0.2.0 patches the issue. | |
| Title | StudioCMS has an Authorization Bypass Through User-Controlled Key | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-28T15:08:38.778Z
Reserved: 2026-01-21T18:38:22.474Z
Link: CVE-2026-24134
Updated: 2026-01-28T15:08:32.325Z
Status : Analyzed
Published: 2026-01-28T00:15:50.330
Modified: 2026-03-17T15:39:51.403
Link: CVE-2026-24134
No data.
OpenCVE Enrichment
Updated: 2026-04-18T02:00:10Z
Github GHSA