Description
The REST API getUsers endpoint in StudioCMS uses the attacker-controlled rank query parameter to decide whether owner accounts should be filtered from the result set.
Recommendation
Update the studiocms package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.4.3
- Patched version(s): 0.4.4
References
Could your website be exposed too?
SmartScanner can check your website for StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens and gives you actionable findings to investigate.
Start a free scanRelated Issues
- StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation - CVE-2026-32103
- StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts - CVE-2026-32106
- Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-plugin - CVE-2026-45321
- Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys - @tanstack/router-vite-plugin - CVE-2026-45321
You might also like:
See something that needs correcting? Let us knowUpdated March 18, 2026


