CVE-2026-30944 is a high-severity privilege escalation vulnerability impacting StudioCMS versions prior to 0.4.0. An authenticated user, even with editor privileges, can generate API tokens for any other user, including administrative accounts, by exploiting an authorization bypass on a specific API endpoint. This network-exploitable flaw has low attack complexity and a CVSS score of 8.8, enabling full compromise of confidentiality, integrity, and availability for the targeted user. While no public exploit code or active exploitation has been observed, immediate upgrade to version 0.4.0 is recommended to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.0CPE matchmatch criteria | cpe:2.3:a:studiocms:studiocms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.