StudioCMS (an Astro-native, server-side-rendered headless CMS) versions prior to 0.2.0 contain a Broken Object Level Authorization (BOLA) issue in the Content Management feature. The content management edit endpoint (/dashboard/content-management/edit) fails to enforce proper object-level authorization and role checks for draft content, allowing a low-privilege user with the "Visitor" role to access draft content created by higher-privilege roles (Editor/Admin/Owner) by supplying/guessing a valid content UUID in the edit URL. The issue is patched in StudioCMS 0.2.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a Python Proof-of-Concept exploit for CVE-2026-24134 (Broken Object Level Authorization / IDOR) in StudioCMS <= 0.1.1. The core idea is that authorization checks for draft content were performed client-side, allowing a low-privileged authenticated user (e.g., Visitor) to directly access draft content belonging to higher-privileged users by requesting an endpoint with a known UUID. Structure: - LICENSE: MIT. - README.md: explains the vulnerability, prerequisites (requests, colorama), manual and automated usage, expected status codes (200 vulnerable, 403 patched, etc.), and mitigation guidance. - cve_2026_24134_poc.py: main exploit script. Exploit capabilities (from code/README): - Authenticates to the target via POST /studiocms_api/auth/login and captures the auth_session cookie. - Optionally verifies/infer role by GET /dashboard and searching response text for role keywords. - Performs the BOLA/IDOR attempt by requesting draft content using a user-supplied UUID (the exploit method is truncated in the provided content, but README indicates it accesses an edit/draft content endpoint and treats HTTP 200 as successful unauthorized access). - Can save retrieved draft content to a local file named draft_{uuid}.html. - Provides an automated test mode that logs in as a Visitor and an Editor to validate whether the Visitor can access the same draft UUID, then reports whether the instance is vulnerable. Notable observables: - Network endpoints: /studiocms_api/auth/login and /dashboard are explicitly present in code; the draft-content endpoint is implied by README but not visible due to truncation. - Authentication artifact: auth_session cookie used as the session token. Overall assessment: This is a functional PoC exploit (not just detection) that demonstrates unauthorized access to protected draft content via UUID-based direct object reference, with basic automation and optional data exfiltration to a local HTML file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.