CVE-2026-63506
- Gepubliceerd16 sep 2026
Beschrijving
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.
CVSS 3.1-ontleding
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHerstel
Er is geen opgeloste versie vastgelegd in de NVD-data. Raadpleeg het leveranciersadvies voor de laatste richtlijnen.
Referenties
- https://github.com/tinacms/tinacms/commit/0a927a4f8d228dd05ee7ca4be32899bc190e73af
- https://github.com/tinacms/tinacms/pull/7168
- https://github.com/tinacms/tinacms/releases/tag/[email protected]
- https://github.com/tinacms/tinacms/releases/tag/@tinacms/[email protected]
- https://github.com/tinacms/tinacms/security/advisories/GHSA-g74q-6g2f-874x
Gerelateerde CVE's
Recente ernstige kwetsbaarheden met hetzelfde zwakhedentype.
Veelgestelde vragen
Wordt CVE-2026-63506 actief misbruikt?
CVE-2026-63506 staat niet in de CISA KEV-catalogus.
Hoe ernstig is CVE-2026-63506?
CVE-2026-63506 heeft een CVSS 3.1-basisscore van 8.8, beoordeeld als high.
Hoe verhelp ik CVE-2026-63506?
Pas de patch of het advies van de leverancier toe en controleer dat er geen getroffen versies meer op uw apparaten staan.
Hoe Secuno hiermee omgaat
Secuno correleert kwetsbaarheden zoals CVE-2026-63506 dagelijks tegen de werkelijke software-inventaris op elk beheerd apparaat. In plaats van een statische ernst wordt elke match in context gescoord: exploitbeschikbaarheid, EPSS, de blootstelling van het asset en bedrijfskriticiteit bepalen de prioriteit. Als een getroffen versie ergens in uw portfolio aanwezig is, verschijnt die automatisch met een geprioriteerd hersteltraject.
Data uit de NVD, CISA KEV-catalogus en FIRST EPSS. CVSS 3.1-basisscore getoond indien beschikbaar.