CVE-2026-63506
Published:September 16, 2026
Updated:October 09, 2026
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.
Affected Packages
https://github.com/tinacms/tinacms.git (GITHUB):
Affected version(s) >=next-tinacms-azure@0.2.0 <next-tinacms-azure@15.0.1Fix Suggestion:
Update to version next-tinacms-azure@15.0.1https://github.com/tinacms/tinacms.git (GITHUB):
Affected version(s) >=@tinacms/auth@0.50.1 <@tinacms/auth@1.1.4Fix Suggestion:
Update to version @tinacms/auth@1.1.4@tinacms/auth (NPM):
Affected version(s) >=0.0.0-a1ff961-20250623024558 <1.1.4Fix Suggestion:
Update to version 1.1.4next-tinacms-azure (NPM):
Affected version(s) >=0.0.0-a1ff961-20250623024558 <15.0.1Fix Suggestion:
Update to version 15.0.1Related Resources (8)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.7
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
HIGH
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
8.8
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Weakness Type (CWE)
Authorization Bypass Through User-Controlled Key
EPSS
Base Score:
0.52