Authorization Vulnerability in Tina CMS by TinaCMS
CVE-2026-63506
8.8HIGH
What is CVE-2026-63506?
A vulnerability in Tina CMS allows an attacker with any TinaCloud account to insert their own app ID and valid token to bypass authorization checks. This enables unauthorized access to media resources and content management operations, including listing, reading, uploading, or deleting content across tenant boundaries. Users are advised to update to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1 to mitigate this risk. For a detailed overview, consult the official advisories and changelogs.
Affected Version(s)
auth < 1.1.4
next-tinacms-azure < 15.0.1
tinacms < 1.1.4
