Unknown · Azuriom Cms · CVE-2026-54415
**Name of the Vulnerable Software and Affected Versions**
Azuriom CMS versions prior to 1.2.11
**Description**
Missing authorization in the server management routes allows an authenticated attacker with the `admin.access` permission to create AzLink server tokens. This can lead to the takeover of non-admin user accounts by modifying their passwords and email addresses through crafted HTTP requests to the '/admin/servers/create' endpoint and the AzLink API endpoints '/api/azlink/password', '/api/azlink/email', and '/api/azlink/user/{id}'.
**Recommendations**
Update to version 1.2.11 or later.