Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-667w-mmh7-mrr4 | StudioCMS has Privilege Escalation via Insecure API Token Generation |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 10 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least Editor) to generate API tokens for any other user, including owner and admin accounts. The endpoint fails to validate whether the requesting user is authorized to create tokens on behalf of the target user ID, resulting in a full privilege escalation. This vulnerability is fixed in 0.4.0. | |
| Title | StudioCMS Affected by Privilege Escalation via Insecure API Token Generation | |
| Weaknesses | CWE-639 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-10T17:34:22.878Z
Reserved: 2026-03-07T17:34:39.979Z
Link: CVE-2026-30944
Updated: 2026-03-10T17:33:54.256Z
Status : Received
Published: 2026-03-10T18:18:54.260
Modified: 2026-03-10T18:18:54.260
Link: CVE-2026-30944
No data.
OpenCVE Enrichment
No data.
Github GHSA