THREAT OPS › Threat News › [NVD] CVE-2026-54415 (HIGH 8.1) — Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their
[NVD] CVE-2026-54415 (HIGH 8.1) — Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their
CVE-2026-54415 CVSS: 8.1 HIGH Published: 2026-06-17T15:17:00.763
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP request
MITRE ATT&CK techniques
- Email AddressesT1589.002
Indicators of compromise
- CVE-2026-54415cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54415