Vulnerability in Tina Content Management System Affecting Storage Operations
CVE-2026-59992

5.4MEDIUM

Key Information:

Vendor

Tinacms

Vendor
CVE Published:
19 August 2026

What is CVE-2026-59992?

A serious flaw in the Tina content management system allows authenticated users to exploit first-party production media adapters that improperly handle object keys during upload and delete operations. This vulnerability enables an authenticated CMS editor to create or delete objects across the storage boundaries defined by the deployment's storage credentials, potentially affecting other tenants and non-media objects. It is essential for users to upgrade to the patched versions of the Tina CMS products to mitigate this risk and secure their media operations.

Affected Version(s)

next-tinacms-azure < 14.0.4

next-tinacms-cloudinary < 26.0.4

next-tinacms-dos < 23.0.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.