Missing Authorization Vulnerability in Bludit CMS Affects User Content Privacy
CVE-2026-93365
7.1HIGH
What is CVE-2026-93365?
Bludit CMS versions up to 3.22.0 are susceptible to a missing authorization vulnerability that permits authenticated users with Author or Editor roles to gain unauthorized access to private drafts and scheduled posts from other users, including administrators. By exploiting the content-get-list AJAX endpoint, attackers can issue a GET request to the admin AJAX endpoint with the draft parameter set to true. This allows them to bypass ownership constraints, thereby exposing sensitive unpublished material and notes contained within administrator-owned drafts.
Affected Version(s)
Bludit CMS 0 <= 3.22.0
Bludit CMS 0 <= 4.0.0-beta-1
Bludit CMS 0 <= 074773eff34b91c002ab9d99029a3edca4934bf1
