Authorization Vulnerability in Tina CMS by TinaCMS
CVE-2026-63506

8.8HIGH

Key Information:

Vendor

Tinacms

Vendor
CVE Published:
16 September 2026

What is CVE-2026-63506?

A vulnerability in Tina CMS allows an attacker with any TinaCloud account to insert their own app ID and valid token to bypass authorization checks. This enables unauthorized access to media resources and content management operations, including listing, reading, uploading, or deleting content across tenant boundaries. Users are advised to update to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1 to mitigate this risk. For a detailed overview, consult the official advisories and changelogs.

Affected Version(s)

auth < 1.1.4

next-tinacms-azure < 15.0.1

tinacms < 1.1.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.