CVE-2026-32638
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `get
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API getUsers endpoint in StudioCMS uses the attacker-controlled rank query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin token can request rank=owner and receive owner account records, including IDs, usernames, display names, and email addresses, even though the adjacent getUser endpoint correctly blocks admins from viewing owner users.
This is an authorization inconsistency inside the same user-management surface. Version 0.4.4 fixes the issue.
LOW · CVSS 2.7
EPSS 0.00026
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0