Authentication Bypass in MaxSite CMS by MaxSite Technology
CVE-2026-70552

9.3CRITICAL

Key Information:

Vendor

Maxsite

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70552?

MaxSite CMS versions 109.5 and earlier are susceptible to an authentication bypass vulnerability in the AJAX dispatcher. This flaw permits unauthenticated attackers to access restricted admin-gated endpoints by manipulating the X-Requested-With header. By requesting a base64-encoded path that resolves to any *-ajax.php file, attackers can exploit this vulnerability to reach privileged plugin endpoints without needing valid credentials. Consequently, they can perform unauthorized actions, such as altering poll states and vote counts, thereby significantly increasing the potential damage stemming from operations intended only for administrative users.

Affected Version(s)

MaxSite CMS 0.78 <= 109.5

MaxSite CMS 0.78 <= 109.5

MaxSite CMS 109.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amir Aliu & Enrik Mustafa
.