Vulnerability in Tina Content Management System Affecting Storage Operations
CVE-2026-59992
5.4MEDIUM
What is CVE-2026-59992?
A serious flaw in the Tina content management system allows authenticated users to exploit first-party production media adapters that improperly handle object keys during upload and delete operations. This vulnerability enables an authenticated CMS editor to create or delete objects across the storage boundaries defined by the deployment's storage credentials, potentially affecting other tenants and non-media objects. It is essential for users to upgrade to the patched versions of the Tina CMS products to mitigate this risk and secure their media operations.
Affected Version(s)
next-tinacms-azure < 14.0.4
next-tinacms-cloudinary < 26.0.4
next-tinacms-dos < 23.0.4
