PT-2026-98954 · Unknown · Bludit Cms

·

CVE-2026-93366

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bludit CMS versions prior to 3.22.1
Description An authorization bypass allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators. This occurs by supplying arbitrary uuid parameters to unprotected AJAX endpoints. Attackers can retrieve page UUIDs for all users via the 'content-get-list' endpoint and then submit crafted POST requests to the 'list-images' and 'delete-image' endpoints in 'bl-kernel/ajax/' to access and destroy media files outside their own pages, bypassing the IMAGE RESTRICT isolation control.
Recommendations Update Bludit CMS to version 3.22.1 or later. Restrict access to the 'bl-kernel/ajax/' endpoints to minimize the risk of exploitation.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93366

Affected Products

Bludit Cms