Vulnerability Description
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Azuriom/Azuriom
- https://github.com/Azuriom/Azuriom/commit/4b744bc0dd11f205f5aa053c6db8a949d3f060
- https://github.com/Azuriom/Azuriom/releases/tag/v1.2.11
FAQ
What is CVE-2026-54415?
CVE-2026-54415 is a vulnerability with a CVSS score of 8.1 (HIGH). Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to crea...
How severe is CVE-2026-54415?
CVE-2026-54415 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54415?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.