PT-2026-94025 · Npm · @Tinacms/Auth+1

CVE-2026-63506

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @tinacms/auth versions prior to 1.1.4 next-tinacms-azure versions prior to 15.0.1
Description Tina is a headless content management system. A cross-tenant authorization bypass exists because the isAuthorized() function accepts a clientID directly from the request and uses it to validate the bearer token via isUserAuthorized() instead of using the site's own configured application ID. An attacker with any TinaCloud account can provide their own app ID and a valid token for that app to a victim's endpoint. This causes the TinaCloudBackendAuthProvider or affected media authorized callbacks to verify the attacker's status based on their own account rather than the victim's tenant boundary.
Technical details include:
  • API Endpoints: /api/cloudinary/media and /api/tina/gql are examples of endpoints that can be targeted.
  • Vulnerable Parameters: The clientID parameter in the request query and the Authorization header are used to bypass security checks.
  • Function Names: The isAuthorized() and isUserAuthorized() functions contain the flawed logic.
Successful exploitation allows an attacker to list, read, upload, or delete media. Additionally, when TinaCloudBackendAuthProvider is utilized, the attacker can perform GraphQL read, create, update, and delete operations on the victim's content without requiring a victim account or any user interaction.
Recommendations Update @tinacms/auth to version 1.1.4. Update next-tinacms-azure to version 15.0.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63506
GHSA-G74Q-6G2F-874X

Affected Products

@Tinacms/Auth
Next-Tinacms-Azure