{"apiVersion":"1.0","identifier":"CVE-2026-59992","description":"Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete operations without enforcing the operator-s configured mediaRoot. In packages/next-tinacms-s3/src/handlers.ts, createMediaHandler accepts req.query.key for a signed PutObject URL and the DELETE path uses req.query.media as the DeleteObjectCommand key. The same missing key-boundary check exists in packages/next-tinacms-dos/src/handlers.ts, packages/next-tinacms-azure/src/handlers.ts, and packages/next-tinacms-cloudinary/src/handlers.ts. An authenticated CMS editor can therefore create or delete objects anywhere the deployment-s storage credential can reach, including other tenants- or non-media objects. These issues are fixed in next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4.","publishedAt":"2026-08-19T22:16:40","lastModifiedAt":"2026-08-21T17:16:32","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59992","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","epssProbability":0.00279,"riskScore":0.55,"affectedProduct":"next-tinacms-s3","affectedVersions":"<23.0.4","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-59992","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-59992","en":"https://www.redsauce.net/en/cves/CVE-2026-59992","fr":"https://www.redsauce.net/fr/cves/CVE-2026-59992","pt":"https://www.redsauce.net/pt/cves/CVE-2026-59992","de":"https://www.redsauce.net/de/cves/CVE-2026-59992","sk":"https://www.redsauce.net/sk/cves/CVE-2026-59992","el":"https://www.redsauce.net/el/cves/CVE-2026-59992"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-59992"}}