Missing Authorization Vulnerability in Bludit CMS Affects User Content Privacy
CVE-2026-93365

7.1HIGH

Key Information:

Vendor

Bludit

Vendor
CVE Published:
25 September 2026

What is CVE-2026-93365?

Bludit CMS versions up to 3.22.0 are susceptible to a missing authorization vulnerability that permits authenticated users with Author or Editor roles to gain unauthorized access to private drafts and scheduled posts from other users, including administrators. By exploiting the content-get-list AJAX endpoint, attackers can issue a GET request to the admin AJAX endpoint with the draft parameter set to true. This allows them to bypass ownership constraints, thereby exposing sensitive unpublished material and notes contained within administrator-owned drafts.

Affected Version(s)

Bludit CMS 0 <= 3.22.0

Bludit CMS 0 <= 4.0.0-beta-1

Bludit CMS 0 <= 074773eff34b91c002ab9d99029a3edca4934bf1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akıner Kısa (`akinerkisa`)
.