Authorization Bypass in Bludit CMS by Bludit
CVE-2026-93366
5.3MEDIUM
What is CVE-2026-93366?
Bludit CMS versions before 3.22.0 are vulnerable to an authorization bypass that permits authenticated users with the Author role to access and manipulate media files from pages owned by other users, including those of administrators. This is achieved by exploiting unprotected AJAX endpoints. Attackers can enumerate page UUIDs through the content-get-list endpoint and subsequently issue crafted POST requests to the list-images and delete-image endpoints, allowing unauthorized access and potential deletion of media assets beyond their own permissions, circumventing existing control measures.
Affected Version(s)
Bludit CMS 0 <= 3.22.0
Bludit CMS 0 <= 4.0.0-beta-1
Bludit CMS 0 <= 074773eff34b91c002ab9d99029a3edca4934bf1
