Unknown · Bludit Cms · CVE-2026-93365
**Name of the Vulnerable Software and Affected Versions**
Bludit CMS versions prior to 3.22.1
**Description**
Authenticated users with the Author or Editor role can access the full content of private drafts and scheduled posts from any other user, including administrators. This occurs via the `content-get-list` AJAX endpoint located at `bl-kernel/ajax/content-get-list.php`. By sending an authenticated GET request to this endpoint with the `draft` parameter set to true, the `getList()` function is triggered without ownership constraints. This results in the return of serialized page objects from across the site, exposing sensitive notes and pre-publication material.
**Recommendations**
Update Bludit CMS to version 3.22.1 or later.
As a temporary mitigation, restrict access to the `bl-kernel/ajax/content-get-list.php` endpoint for users with Author or Editor roles.