Description
StudioCMS contains a Broken Object Level Authorization (BOLA) vulnerability in the Content Management feature that allows users with the “Visitor” role to access draft content created by Editor/Admin/Owner users.
Recommendation
Update the studiocms package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.0
- Patched version(s): 0.2.0
References
Could your website be exposed too?
SmartScanner can check your website for StudioCMS has Authorization Bypass Through User-Controlled Key and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Authorization Bypass Through User-Controlled Key in urijs - CVE-2022-0613
- Authorization Bypass Through User-Controlled Key in url-parse - CVE-2022-0686
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
- StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Check - CVE-2026-32101


