Cross-Origin Iframe Vulnerability in Tina CMS by Tina
CVE-2026-108261

9.3CRITICAL

Key Information:

Vendor

Tinacms

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108261?

Tina CMS, a headless content management system, has a vulnerability in its admin preview route that can allow unauthenticated attackers to exploit vulnerabilities linked to frame origins. This flaw occurs prior to versions 3.14.0 and 2.5.14 of Tina CMS and @tinacms/app, where an attacker can craft a URL leading to an off-origin iframe. If a signed-in editor follows this link, the attacker can gain unauthorized access to execute GraphQL operations using the editor's credentials, thereby exposing or altering protected content. This security flaw has been addressed in the latest releases, urging users to upgrade to the fixed versions.

Affected Version(s)

app < 2.5.14

tinacms < 3.14.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.