Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93366— Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints

Quick assessment

Affected
Bludit Bludit CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bludit CMS 3.22.0 及之前版本存在一个授权绕过漏洞,允许具有“作者”(Author)角色的已认证用户通过向未受保护的 AJAX 端点提供任意的 UUID 参数,枚举并删除属于其他用户(包括管理员)所拥有页面的媒体文件。攻击者可以通过 content-get-list 端点获取所有用户的页面 UUID,然后向 bl-kernel/ajax/ 下的 list-images 和 delete-image 端点提交构造的 POST 请求,从而访问并销毁其自有页面之外的媒体文件,从而绕过 IMAGE_REST

CVSS 5.4 · Medium EPSS 0.19% · P8

Affected Version Matrix 3

VendorProduct Version RangeStatus
Bludit Bludit CMS ≤ 3.22.0 affected
≤ 4.0.0-beta-1 affected
≤ 074773eff34b91c002ab9d99029a3edca4934bf1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93366

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators, by supplying arbitrary uuid parameters to unprotected AJAX endpoints. Attackers can retrieve page UUIDs for all users via the content-get-list endpoint and then submit crafted POST requests to the list-images and delete-image endpoints in bl-kernel/ajax/ to access and destroy media files outside their own pages, bypassing the IMAGE_RESTRICT isolation control.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Bludit Bludit CMS 0 ~ 3.22.0 -

II. Public POCs for CVE-2026-93366

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93366

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-93366 (1)

Proof of Concept for CVE-2026-93366 (1)

Same Patch Batch · Bludit · 2026-09-25 · 3 CVEs total

CVE-2026-93365 6.5 MEDIUM Bludit CMS 3.22.0 Missing Authorization via content-get-list AJAX Endpoint
CVE-2026-93364 4.3 MEDIUM Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()

IV. Related Vulnerabilities

V. Comments for CVE-2026-93366

No comments yet


Leave a comment