<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T12:11:58.686918+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-18148</id>
    <title>cnvd-2026-18148</title>
    <updated>2026-10-06T12:11:58.739284+00:00</updated>
    <content>cnvd-2026-18148</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-18148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276571</id>
    <title>EUVD-2026-276571</title>
    <updated>2026-10-06T12:11:58.739335+00:00</updated>
    <content>EUVD-2026-276571</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32638</id>
    <title>fkie_cve-2026-32638</title>
    <updated>2026-10-06T12:11:58.739349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `getUsers` endpoint in StudioCMS uses the attacker-controlled `rank` query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin token can request `rank=owner` and receive owner account records, including IDs, usernames, display names, and email addresses, even though the adjacent `getUser` endpoint correctly blocks admins from viewing owner users. This is an authorization inconsistency inside the same user-management surface. Version 0.4.4 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32638"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xvf4-ch4q-2m24</id>
    <title>GHSA-xvf4-ch4q-2m24 — StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens</title>
    <updated>2026-10-06T12:11:58.739387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: studiocms</p>
<p>## Summary</p>
<p>The REST API `getUsers` endpoint in StudioCMS uses the attacker-controlled `rank` query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin token can request `rank=owner` and receive owner account records, including IDs, usernames, display names, and email addresses, even though the adjacent `getUser` endpoint correctly blocks admins from viewing owner users. This is an authorization inconsistency inside the same user-management surface.</p>
<p>## Details</p>
<p>### Vulnerable Code Path</p>
<p>File: `D:/bugcrowd/studiocms/repo/packages/studiocms/frontend/pages/studiocms_api/_handlers/rest-api/v1/secure.ts`, lines 1605-1647</p>
<p>```ts
.handle(
    'getUsers',
    Effect.fn(
        function* ({ urlParams: { name, rank, username } }) {
            if (!restAPIEnabled) {
                return yield* new RestAPIError({ error: 'Endpoint not found' });
            }
            const [sdk, user] = yield* Effect.all([SDKCore, CurrentRestAPIUser]);</p>
<p>if (user.rank !== 'owner' &amp;&amp; user.rank !== 'admin') {
                return yield* new RestAPIError({ error: 'Unauthorized' });
            }</p>
<p>const allUsers = yield* sdk.GET.users.all();
            let data = allUsers.map(...);</p>
<p>if (rank !== 'owner') {
                data = data.filter((user) =&gt; user.rank !== 'owner');
            }</p>
<p>if (rank) {
                data = data.filter((user) =&gt; user.rank === rank);
            }</p>
<p>return…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xvf4-ch4q-2m24"/>
  </entry>
</feed>
