CVE-2026-54415
HIGHBroken Access Control in Azuriom CMS Server Routes Allows Account Takeover
Title source: cnaDescription
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
release-notes
patch
Azuriom CMS v1.2.11 Release
https://github.com/Azuriom/Azuriom/releases/tag/v1.2.11
Patch patch
Fixes and improvements (patch commit)
https://github.com/Azuriom/Azuriom/commit/4b744bc0dd11f205f5aa053c6db8a949d3f0608e
Scores
CVSS v3
8.1
EPSS
0.0035
EPSS Percentile
26.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
CWE-862
Status
published
Products (1)
Azuriom/Azuriom CMS
< 1.2.11
Published
Jun 17, 2026
Tracked Since
Jun 17, 2026