Description
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass across TinaCloud and self‑hosted sites
Action: Patch
AI Analysis

Impact

The vulnerability is a CWE‑639 Broken Access Control flaw. It occurs when Tina’s isAuthorized function accepts a clientID supplied in the request and validates the bearer token against the TinaCloud application instead of the self‑hosted site's own app. An attacker with a TinaCloud account can use their own app ID and a valid token to trick the backend into treating the attacker as a legitimate user. This allows the attacker to list, read, upload, delete media and, when the TinaCloudBackendAuthProvider is employed, perform GraphQL read, create, update and delete operations on the victim’s content without needing a victim account or interaction.

Affected Systems

Vulnerable products include @tinacms/auth and next-tinacms-azure in the tinacms open‑source framework. Prior to version 1.1.4 of @tinacms/auth and version 15.0.1 of next-tinacms-azure, the buggy logic exists in the source files packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is less than 1%, suggesting a low probability of widespread exploitation at the moment, and the vulnerability is not yet listed in the CISA KEV catalog. However, the flaw permits an attacker to gain full authorisation on the victim site by supplying a malicious clientID, leading to complete compromise of content and media resources if the vulnerable versions are deployed. The attack requires an attacker to possess a TinaCloud account, a valid token, and the ability to send requests to the victim endpoint. The benefit to the attacker is practically total control over the victim's content without direct tenant interaction.

Generated by OpenCVE AI on September 18, 2026 at 01:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @tinacms/auth to version 1.1.4 or newer
  • Upgrade next-tinacms-azure to version 15.0.1 or newer
  • If upgrading immediately is not feasible, restrict the clientID parameter or disable the legacy authentication endpoint and monitor API traffic for anomalous use of external clientIDs

Generated by OpenCVE AI on September 18, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g74q-6g2f-874x Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tina
Tina tinacms
Tinacms
Tinacms next-tinacms-azure
Vendors & Products Tina
Tina tinacms
Tinacms
Tinacms next-tinacms-azure

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.
Title Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Tina Tinacms
Tinacms Next-tinacms-azure
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:54:38.071Z

Reserved: 2026-07-16T21:49:52.069Z

Link: CVE-2026-63506

cve-icon Vulnrichment

Updated: 2026-09-17T15:54:29.911Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:13.163

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-63506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key