CVE-2026-70552: MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php

Published Aug 4, 2026
·
Updated

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any -ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.

Affected Software

1 affected component
Maxsite MaxSite CMS<=109.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MaxSite CMS to a version that resolves this vulnerability.

    Fixed in 109.5
  2. Configuration

    Patch/adjust ajax.php AJAX dispatcher so unauthenticated requests cannot bypass admin gating; specifically, do not honor the presence of an X-Requested-With header as an authentication substitute.

    MaxSite CMS AJAX dispatcher (ajax.php) Authentication requirement for admin-gated *-ajax.php endpoints = Require valid authentication (reject unauthenticated requests even if X-Requested-With header is supplied)
  3. Compensating control

    Add compensating access control for AJAX dispatcher routes so unauthenticated users cannot reach admin-gated endpoints (e.g., via web server/WAF rules limiting access to ajax.php/*-ajax.php to authenticated sessions only).

Event History

Aug 4, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203