PT-2026-94025 · Npm · @Tinacms/Auth+1
CVE-2026-63506
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
@tinacms/auth versions prior to 1.1.4
next-tinacms-azure versions prior to 15.0.1
Description
Tina is a headless content management system. A cross-tenant authorization bypass exists because the
isAuthorized() function accepts a clientID directly from the request and uses it to validate the bearer token via isUserAuthorized() instead of using the site's own configured application ID. An attacker with any TinaCloud account can provide their own app ID and a valid token for that app to a victim's endpoint. This causes the TinaCloudBackendAuthProvider or affected media authorized callbacks to verify the attacker's status based on their own account rather than the victim's tenant boundary.Technical details include:
- API Endpoints:
/api/cloudinary/mediaand/api/tina/gqlare examples of endpoints that can be targeted. - Vulnerable Parameters: The
clientIDparameter in the request query and theAuthorizationheader are used to bypass security checks. - Function Names: The
isAuthorized()andisUserAuthorized()functions contain the flawed logic.
Successful exploitation allows an attacker to list, read, upload, or delete media. Additionally, when
TinaCloudBackendAuthProvider is utilized, the attacker can perform GraphQL read, create, update, and delete operations on the victim's content without requiring a victim account or any user interaction.Recommendations
Update @tinacms/auth to version 1.1.4.
Update next-tinacms-azure to version 15.0.1.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Tinacms/Auth
Next-Tinacms-Azure