CVE-2026-63506: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site

Published Sep 16, 2026
·
Updated

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.

Affected Software

2 affected components
Tina npm/@tinacms/auth<1.1.4
npm/next-tinacms-azure<15.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade packages/@tinacms/auth to a version that resolves this vulnerability.

    Fixed in 1.1.4
  2. Upgrade

    Upgrade packages/next-tinacms-azure to a version that resolves this vulnerability.

    Fixed in 15.0.1

Event History

Sep 16, 2026
CVE Published
via MITRE·08:27 PM
Data Sourced
via MITRE·08:27 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any user with a TinaCloud account can exploit an affected self-hosted site. The attacker does not need an account for the victim site or any interaction from a victim user.

2

What does an attacker need to submit?

The attacker needs their own TinaCloud app ID and a valid bearer token for that app. They can provide the app ID through the request-controlled clientID field so authorization is checked against their app rather than the victim site's configured app.

3

Which site capabilities can be exposed?

Affected media authorization callbacks can permit media listing, reading, upload, or deletion. Sites using TinaCloudBackendAuthProvider can additionally permit GraphQL read, create, update, and delete operations against victim content.

4

Which versions contain the fix?

Update @tinacms/auth to 1.1.4 or later and next-tinacms-azure to 15.0.1 or later. The issue affects versions prior to those releases.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203