CVE-2026-30944Disclosure(studiocms / studiocms)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch studiocms studiocms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least Editor) to generate API tokens for any other user, including owner and admin accounts. The endpoint fails to validate whether the requesting user is authorized to create tokens on behalf of the target user ID, resulting in a full privilege escalation. This vulnerability is fixed in 0.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • studiocms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-10); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
studiocms

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-17: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-17: 203-1003-17
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure1Patch1
2026-03-172
Disclosure2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30944 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any aut… https://www.cve.org/CVERecord?id=CVE-2026-30944

    Post summary

    The text mentions CVE-2026-30944 and notes that prior to version 0.4.0 the /studiocms_api/dashboard/api-tokens endpoint is vulnerable, but does not provide any PoC, exploit, patch, or evidence of active exploitation.

    00010180
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30944 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any aut… https://www.cve.org/CVERecord?id=CVE-2026-30944 ----- Traducción: CVE-2026-30944 Stu… http://infoflow.cloud`

    Post summary

    CVE-2026-30944 discloses an authentication bypass in StudioCMS’s /studiocms_api/dashboard/api-tokens endpoint prior to version 0.4.0, as reported on the CVE record.

    0000044
    60 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30944: HIGH] Security alert! StudioCMS fixed a privilege escalation vulnerability in version 0.4.0. Check and update your system to protect against unauthorized API token generation.#cve,CVE-2026-30944,#cybersecurity https://cvefind.com/CVE-2026-30944

    Post summary

    StudioCMS has released a fix for the high‑severity privilege escalation CVE-2026-30944; users are urged to update to version 0.4.0 or newer to remediate the issue.

    0000049
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30944 - High StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least... https://www.thehackerwire.com/vulnerability/CVE-2026-30944/ https://t.co/Tqqc7kPYnd

    Post summary

    The tweet announces a discovered high‑severity vulnerability in StudioCMS affecting the /studiocms_api/dashboard/api-tokens endpoint, without providing PoC, exploit, or patch details.

    0000029
    133 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstudiocmsstudiocms---

Explore more