
CVE-2026-32106 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API createUser endpoint uses string-based rank checks … https://www.cve.org/CVERecord?id=CVE-2026-32106
Post summary
The notice discloses that StudioCMS prior to 0.4.3 uses string-based rank checks in its REST API createUser endpoint, indicating a potential vulnerability, but provides no PoC, exploit, or patch details.
