Authentication Bypass in MaxSite CMS by MaxSite Technology
CVE-2026-70552
9.3CRITICAL
What is CVE-2026-70552?
MaxSite CMS versions 109.5 and earlier are susceptible to an authentication bypass vulnerability in the AJAX dispatcher. This flaw permits unauthenticated attackers to access restricted admin-gated endpoints by manipulating the X-Requested-With header. By requesting a base64-encoded path that resolves to any *-ajax.php file, attackers can exploit this vulnerability to reach privileged plugin endpoints without needing valid credentials. Consequently, they can perform unauthorized actions, such as altering poll states and vote counts, thereby significantly increasing the potential damage stemming from operations intended only for administrative users.
Affected Version(s)
MaxSite CMS 0.78 <= 109.5
MaxSite CMS 0.78 <= 109.5
MaxSite CMS 109.6
