Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.0 Node.js & npm GHSA-g74q-6g2f-874x CVE-2026-63506

Tina CMS Authorization Bypass Lets Any TinaCloud User Access Self-Hosted Sites (CVE-2026-63506)

A flaw in @tinacms/auth and next-tinacms-azure allows any TinaCloud account holder to authorize against a victim's self-hosted Tina site by supplying their own app ID, enabling unauthorized content and media access.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A vulnerability in Tina, a headless content management system, allows an authorization check to be bypassed across tenant boundaries. The issue affects the @tinacms/auth and next-tinacms-azure npm packages and has been assigned CVE-2026-63506 with a CVSS score of 8.8 (High). Fixed versions are available for both affected packages.

What Happened

A broken access control issue was identified in Tina's authorization logic. The function isAuthorized accepts a client ID supplied by the incoming request and passes it to isUserAuthorized to validate a bearer token, rather than checking the token against the self-hosted site's own configured TinaCloud app. This means the client ID used for validation is controlled by the requester, not fixed to the site being accessed.

Technical Cause

The vulnerable code resides in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Because the authorization routine trusts a request-controlled client/app ID instead of enforcing the victim site's configured app, an attacker holding any valid TinaCloud account and token can submit their own app ID alongside their own valid bearer token to a victim's endpoint. The victim's TinaCloudBackendAuthProvider or an affected media authorization callback then validates the token against the attacker's own TinaCloud app — which succeeds, since the attacker legitimately owns that app and token — and incorrectly treats the attacker as authorized for the victim's tenant. This is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).

Why It Matters

Successful exploitation allows an attacker to list, read, upload, or delete media on the victim's self-hosted Tina site. Where TinaCloudBackendAuthProvider is in use, the attacker can also perform GraphQL read, create, update, and delete operations against the victim's content. Critically, this requires no victim account, no victim credentials, and no interaction from the victim — the attacker only needs their own TinaCloud account and token, and knowledge of or access to a victim endpoint.

Affected Versions

@tinacms/auth versions up to and including 1.1.3 are affected. next-tinacms-azure versions up to and including 15.0.0 are affected.

Fixes and Mitigation

The vulnerability is fixed in @tinacms/auth version 1.1.4 and next-tinacms-azure version 15.0.1. Sites using either package should upgrade to the fixed version to restore correct enforcement of the self-hosted site's own configured app during authorization checks.

Recommended Action

Operators of self-hosted Tina deployments using @tinacms/auth or next-tinacms-azure should update to @tinacms/auth 1.1.4 or next-tinacms-azure 15.0.1 as applicable without delay. Given the lack of required victim interaction and the potential for unauthorized content and media operations, this update should be prioritized, particularly for sites relying on TinaCloudBackendAuthProvider.

PatchBriefing score

5.0 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Why this score

This issue carries a CVSS score of 8.8 (High), driven primarily by its network attack vector, low attack complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. The patchwire_score of 5 reflects the absence of confirmed exploitation in the wild, no known public exploit code, and no EPSS data indicating elevated near-term exploitation likelihood, while still accounting for the no-user-interaction factor. A fix is available for both affected packages.

Affected versions

@tinacms/auth <= 1.1.3
vulnerable
≥ 1.1.4
patched
next-tinacms-azure <= 15.0.0
vulnerable
≥ 15.0.1
patched

Reported fixes

The vulnerability is fixed in @tinacms/auth version 1.1.4 and next-tinacms-azure version 15.0.1. Sites using either package should upgrade to the fixed version to restore correct enforcement of the self-hosted site's own configured app during authorization checks.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Tina CMS Authorization Bypass Lets Any TinaCloud User Access Self-Hosted Sites (CVE-2026-63506)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email