No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 10 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Azuriom CMS - Broken Access Control in Server Routes Allows Account Takeover | Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover |
Mon, 10 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover | Azuriom CMS - Broken Access Control in Server Routes Allows Account Takeover |
Thu, 25 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Azuriom
Azuriom azuriom |
|
| Vendors & Products |
Azuriom
Azuriom azuriom |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}). | |
| Title | Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover | |
| Weaknesses | CWE-269 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-10T11:44:04.575Z
Reserved: 2026-06-13T16:39:46.122Z
Link: CVE-2026-54415
Updated: 2026-06-17T15:41:09.630Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T13:15:03Z