CVE-2026-32638 PUBLISHED

StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens

Assigner: GitHub_M
Reserved: 12.03.2026 Published: 18.03.2026 Updated: 19.03.2026

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API getUsers endpoint in StudioCMS uses the attacker-controlled rank query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin token can request rank=owner and receive owner account records, including IDs, usernames, display names, and email addresses, even though the adjacent getUser endpoint correctly blocks admins from viewing owner users. This is an authorization inconsistency inside the same user-management surface. Version 0.4.4 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 2.7

Product Status

Vendor withstudiocms
Product studiocms
Versions
  • Version < 0.4.4 is affected

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE