SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59992

MEDIUM · CVSS 5.4 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Tina headless content management system, where first-party media adapters allow authenticated CMS editors to manipulate storage object keys without proper validation, potentially enabling unauthorized creation or deletion of objects across different tenants or non-media files. This could lead to data loss or exposure, making it critical for organizations using affected versions of next-tinacms-s3, next-tinacms-dos, next-tinacms-azure, and next-tinacms-cloudinary to prioritize updating to the patched versions. Users of these CMS packages should assess their deployment configurations and apply the necessary updates to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59992
Severity
MEDIUM
CVSS
5.4
EPSS
0.28%

Original NVD Description

Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete operations without enforcing the operator's configured mediaRoot. In packages/next-tinacms-s3/src/handlers.ts, createMediaHandler accepts req.query.key for a signed PutObject URL and the DELETE path uses req.query.media as the DeleteObjectCommand key. The same missing key-boundary check exists in packages/next-tinacms-dos/src/handlers.ts, packages/next-tinacms-azure/src/handlers.ts, and packages/next-tinacms-cloudinary/src/handlers.ts. An authenticated CMS editor can therefore create or delete objects anywhere the deployment's storage credential can reach, including other tenants' or non-media objects. These issues are fixed in next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4.