Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93364— Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()

Quick assessment

Affected
Bludit Bludit CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bludit CMS 3.22.0 及之前版本中存在一个质量分配(mass assignment)漏洞,允许具有“作者”(Author)角色的已认证用户通过在内容保存请求中注入受限参数,来修改原本仅限管理员使用的特权页面字段。攻击者可以通过 中的 函数提交受限字段(例如 和 ),该函数在遍历 中声明的所有字段时未进行逐字段授权检查,从而导致“作者”角色能够将页面转换为静态的全站导航条目,或将页面所有权转移至任意账户。

CVSS 4.3 · Medium EPSS 0.19% · P7

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 3

VendorProduct Version RangeStatus
Bludit Bludit CMS ≤ 3.22.0 affected
≤ 4.0.0-beta-1 affected
≤ 074773eff34b91c002ab9d99029a3edca4934bf1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93364

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()
Source: CVE Program / CVE List V5
Vulnerability Description
Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can submit reserved fields such as type and username through the Pages::edit() function in bl-kernel/pages.class.php, which iterates all fields declared in dbFields without per-field authorization, enabling an Author to convert pages to static site-wide navigation entries or transfer page ownership to arbitrary accounts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-915
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Bludit Bludit CMS 0 ~ 3.22.0 -

II. Public POCs for CVE-2026-93364

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93364

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-93364 (1)

Proof of Concept for CVE-2026-93364 (1)

Same Patch Batch · Bludit · 2026-09-25 · 3 CVEs total

CVE-2026-93365 6.5 MEDIUM Bludit CMS 3.22.0 Missing Authorization via content-get-list AJAX Endpoint
CVE-2026-93366 5.4 MEDIUM Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints

IV. Related Vulnerabilities

V. Comments for CVE-2026-93364

No comments yet


Leave a comment