CVE 8.1 HIGH

Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover_CVE-2026-54415

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).

Basic Information

ID CVE-2026-54415
Source TuranSec
Published Jun 17, 2026 at 14:04
Modified Jun 17, 2026 at 14:10

Affected Product

Vendor Azuriom
Product Azuriom CMS
Affected Versions Azuriom Azuriom CMS 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.