CVE-2026-59992
Last modified
CVE-2026-59992 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete operations without enforcing the operator's configured mediaRoot. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete operations without enforcing the operator's configured mediaRoot. In packages/next-tinacms-s3/src/handlers.ts, createMediaHandler accepts req.query.key for a signed PutObject URL and the DELETE path uses req.query.media as the DeleteObjectCommand key. The same missing key-boundary check exists in packages/next-tinacms-dos/src/handlers.ts, packages/next-tinacms-azure/src/handlers.ts, and packages/next-tinacms-cloudinary/src/handlers.ts. An authenticated CMS editor can therefore create or delete objects anywhere the deployment's storage credential can reach, including other tenants' or non-media objects. These issues are fixed in next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| tinacms | tinacms | < 23.0.4 |
| tinacms | next-tinacms-s3 | < 23.0.4 |
| tinacms | next-tinacms-dos | < 23.0.4 |
| tinacms | next-tinacms-azure | < 14.0.4 |
| tinacms | next-tinacms-cloudinary | < 26.0.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-59992?
How severe is CVE-2026-59992?
How do I fix CVE-2026-59992?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59982OpenEXR is the reference implementation and specification fo…7.1
- CVE-2026-59983OpenEXR is the reference implementation and specification fo…5.5
- CVE-2026-59984OpenEXR is the reference implementation and specification fo…5.5
- CVE-2026-59985OpenEXR is the reference implementation and specification fo…5.5
- CVE-2026-59989Phalcon is a high-performance, full-stack PHP framework. In …9.2
- CVE-2026-5999A vulnerability has been found in JeecgBoot up to 3.9.1. Thi…6.3
- CVE-2026-59995sftp in OpenSSH before 10.4 does not properly constrain the …5.4
- CVE-2026-59996scp in OpenSSH before 10.4 may place a file in the parent di…5.4
- CVE-2026-59997internal-sftp in sshd in OpenSSH before 10.4 recognizes only…5.4
- CVE-2026-59998sshd in OpenSSH before 10.4 has an undocumented security-rel…6.5
- CVE-2026-59999In sshd in OpenSSH before 10.4, DisableForwarding=yes was su…7.5
- CVE-2026-6000A vulnerability was found in code-projects Online Library Ma…4.3
Are you affected by CVE-2026-59992?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
