CVE-2026-30944 is an authorization flaw in StudioCMS, a server-side-rendered, Astro-native headless CMS. In versions prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint does not properly validate whether the authenticated requester is permitted to create API tokens for the specified target user ID. As a result, any authenticated user with at least Editor privileges can generate API tokens on behalf of arbitrary users, including higher-privileged admin and owner accounts. This is an insecure direct object reference / missing authorization condition on a sensitive object, and successful exploitation leads to full privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Python proof-of-concept exploit for CVE-2026-30945 affecting StudioCMS <= 0.3.0. The vulnerability is an IDOR/BOLA in the API token revocation handler: an authenticated user with editor-level privileges can send a DELETE request to /studiocms_api/dashboard/api-tokens with attacker-controlled tokenID and userID to revoke tokens belonging to other users (including admin/owner), resulting in targeted denial of service against CI/CD, integrations, and monitoring that rely on those tokens. Structure: - README.md: Detailed vulnerability description, impact, prerequisites, and example commands for manual exploitation and automated testing; notes chaining with CVE-2026-30944 (token generation IDOR) for a create-then-revoke workflow. - cve_2026_30945_poc.py: Standalone Python script (requests + colorama) implementing: - Authentication via POST /studiocms_api/auth/login and session cookie handling. - Session verification via POST /studiocms_api/dashboard/verify-session to retrieve user identity and permissionLevel. - Token operations against /studiocms_api/dashboard/api-tokens (delete/revoke for CVE-2026-30945; and an indicated helper to create a token for a target user leveraging CVE-2026-30944). - Optional user enumeration/lookup via /studiocms_api/rest/v1/users. - CLI modes: manual (single account) and --auto-test (multi-role testing), optional --save to JSON, and --no-ssl-verify. Overall purpose: provide an operational PoC to demonstrate and test arbitrary API token revocation (DoS) in vulnerable StudioCMS deployments, including role-based testing and optional chaining with the related token-creation IDOR.
Repository contains a Python proof-of-concept exploit for CVE-2026-30944 affecting StudioCMS <= 0.3.0. Structure is minimal: LICENSE, a detailed README, and a single executable script (cve_2026_30944_poc.py) that performs authentication and privilege escalation. Core capability: the script logs in as a low-privileged user (README indicates at least Editor), then exploits a Broken Object Level Authorization/IDOR in POST /studiocms_api/dashboard/api-tokens by supplying an arbitrary target user UUID in the JSON body ("user": "<uuid>"). Because the server does not validate that the caller is allowed to create tokens for that UUID, the attacker can mint an API token for owner/admin accounts. The script then verifies the impact by using the minted token to access privileged REST API resources (notably GET/usage of /studiocms_api/rest/v1/users as shown in README). Operational features: supports manual mode (single credential set) and an automated test mode intended to compare behavior across roles (editor vs visitor) to confirm the authorization flaw. It includes optional JSON output saving and an option to disable TLS verification. No evidence of destructive actions or unrelated malware behavior was observed in the provided content; it is a focused network/API exploit PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.