Unrated severityNVD Advisory· Published Jun 17, 2026· Updated Jun 17, 2026
Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
CVE-2026-54415
Description
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Azuriom/Azuriom/commit/4b744bc0dd11f205f5aa053c6db8a949d3f0608emitrepatch
- github.com/Azuriom/Azuriom/releases/tag/v1.2.11mitrevendor-advisoryrelease-notespatch
News mentions
0No linked articles in our index yet.