Authorization Bypass in Bludit CMS by Bludit
CVE-2026-93366

5.3MEDIUM

Key Information:

Vendor

Bludit

Vendor
CVE Published:
25 September 2026

What is CVE-2026-93366?

Bludit CMS versions before 3.22.0 are vulnerable to an authorization bypass that permits authenticated users with the Author role to access and manipulate media files from pages owned by other users, including those of administrators. This is achieved by exploiting unprotected AJAX endpoints. Attackers can enumerate page UUIDs through the content-get-list endpoint and subsequently issue crafted POST requests to the list-images and delete-image endpoints, allowing unauthorized access and potential deletion of media assets beyond their own permissions, circumventing existing control measures.

Affected Version(s)

Bludit CMS 0 <= 3.22.0

Bludit CMS 0 <= 4.0.0-beta-1

Bludit CMS 0 <= 074773eff34b91c002ab9d99029a3edca4934bf1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akıner Kısa (`akinerkisa`)
.