CVE-2026-93366: Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints

Published Sep 25, 2026
·
Updated

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators, by supplying arbitrary uuid parameters to unprotected AJAX endpoints. Attackers can retrieve page UUIDs for all users via the content-get-list endpoint and then submit crafted POST requests to the list-images and delete-image endpoints in bl-kernel/ajax/ to access and destroy media files outside their own pages, bypassing the IMAGERESTRICT isolation control.

Affected Software

1 affected component
Bludit Bludit CMS<=3.22.0

Event History

Sep 25, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

An authenticated user with the Author role can exploit the affected AJAX endpoints. No administrator privileges or user interaction are required.

2

What resources can an attacker access or delete?

An Author can enumerate and delete media files associated with pages owned by other users, including administrators. The issue bypasses the IMAGE_RESTRICT isolation control intended to limit access to a user’s own page media.

3

How does exploitation work?

The attacker can obtain page UUIDs for users’ pages through the content-get-list endpoint, then provide arbitrary UUID values in POST requests to the list-images and delete-image endpoints under bl-kernel/ajax/. Affected releases include Bludit CMS through 3.22.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203