CVE-2026-32104 identifies an Insecure Direct Object Reference (IDOR) vulnerability in StudioCMS versions prior to 0.4.3, where the `updateUserNotifications` endpoint fails to verify user ownership. This flaw allows any authenticated user to modify the notification preferences of any other user, including administrators. Rated as Medium severity (CVSS 5.4), it has a low attack complexity and requires only low privileges, as an authenticated attacker can exploit it over the network. The potential impact involves low integrity and availability, as an attacker could disable critical notifications for other users, potentially suppressing alerts about malicious activity. Currently, there is no evidence of active exploitation, and no public exploit code or significant community attention has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.3CPE matchmatch criteria | cpe:2.3:a:studiocms:studiocms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.