PT-2026-98952 · Unknown · Bludit Cms

·

CVE-2026-93364

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bludit CMS versions prior to 3.22.1
Description Authenticated users with the Author role can modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. This occurs because the Pages::edit() function in bl-kernel/pages.class.php iterates through all fields declared in dbFields without performing per-field authorization. An attacker can submit reserved fields such as type and username to convert pages into static site-wide navigation entries or transfer page ownership to arbitrary accounts. Mass assignment is a vulnerability where an application takes user-provided data and binds it to an internal object without proper filtering, allowing the modification of restricted properties.
Recommendations Update Bludit CMS to version 3.22.1 or later. As a temporary mitigation, restrict the permissions of users with the Author role to prevent unauthorized content save requests.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93364

Affected Products

Bludit Cms