Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63506— Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site

Quick assessment

Affected
tinacms tinacms
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tina 是一个无头(headless)内容管理系统(CMS)。在 @tinacms/auth 1.1.4 和 next-tinacms-azure 15.0.1 之前, 函数会接受由请求控制的 ,并调用 针对所选的 TinaCloud 应用来验证 Bearer Token,而不是针对自托管站点所配置的应用进行验证。任何拥有 TinaCloud 账户的攻击者都可以向受害者的端点提交攻击者自己的应用 ID 和有效令牌,从而使得 或受影响的媒体授权回调在租户边界之外接受攻击者的已验证状态。易受攻击的逻辑位于 和 中。成

CVSS 8.8 · High EPSS 0.52% · P42

Possible ATT&CK Techniques 1 AI

T1550 · Use Alternate Authentication Material

Affected Version Matrix 3

VendorProduct Version RangeStatus
@tinacms auth < 1.1.4 affected
tinacms next-tinacms-azure < 15.0.1 affected
tinacms tinacms < 1.1.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63506

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
Source: CVE Program / CVE List V5
Vulnerability Description
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tinacms tinacms < 1.1.4 -
@tinacms auth < 1.1.4 -
tinacms next-tinacms-azure < 15.0.1 -

II. Public POCs for CVE-2026-63506

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63506

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-63506 (2)

Other References for CVE-2026-63506 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-63506

No comments yet


Leave a comment