CVE-2026-30945 affects StudioCMS prior to version 0.4.0. The DELETE /studiocms_api/dashboard/api-tokens endpoint improperly authorizes token revocation requests. The handler accepts tokenID and userID values directly from the client request and does not verify that the targeted token belongs to the caller, that the caller is authorized to act on behalf of the specified user, or that role hierarchy restrictions are enforced. As a result, any authenticated user with editor privileges or higher can revoke API tokens belonging to other users, including admin and owner accounts. The issue is an authorization flaw involving user-controlled object references in a privileged management endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Python proof-of-concept exploit for CVE-2026-30945 affecting StudioCMS <= 0.3.0. The vulnerability is an IDOR/BOLA in the API token revocation handler: an authenticated user with editor-level privileges can send a DELETE request to /studiocms_api/dashboard/api-tokens with attacker-controlled tokenID and userID to revoke tokens belonging to other users (including admin/owner), resulting in targeted denial of service against CI/CD, integrations, and monitoring that rely on those tokens. Structure: - README.md: Detailed vulnerability description, impact, prerequisites, and example commands for manual exploitation and automated testing; notes chaining with CVE-2026-30944 (token generation IDOR) for a create-then-revoke workflow. - cve_2026_30945_poc.py: Standalone Python script (requests + colorama) implementing: - Authentication via POST /studiocms_api/auth/login and session cookie handling. - Session verification via POST /studiocms_api/dashboard/verify-session to retrieve user identity and permissionLevel. - Token operations against /studiocms_api/dashboard/api-tokens (delete/revoke for CVE-2026-30945; and an indicated helper to create a token for a target user leveraging CVE-2026-30944). - Optional user enumeration/lookup via /studiocms_api/rest/v1/users. - CLI modes: manual (single account) and --auto-test (multi-role testing), optional --save to JSON, and --no-ssl-verify. Overall purpose: provide an operational PoC to demonstrate and test arbitrary API token revocation (DoS) in vulnerable StudioCMS deployments, including role-based testing and optional chaining with the related token-creation IDOR.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.