LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32104

studiocms · studiocms

Published
CVSS5.4
Severitymedium
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Description

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNotifications endpoint accepts a user ID from the request payload and uses it to update that user's notification preferences. It checks that the caller is logged in but never verifies that the caller owns the target account (id !== userData.user.id). Any authenticated visitor can modify notification preferences for any user, including disabling admin notifications to suppress detection of malicious activity. This vulnerability is fixed in 0.4.3.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32104

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32104.