CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-70552 — MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in...

·Source: NIST NVD

Updated:

Executive Summary

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials

Analysis

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree. CVSS Score: 9.8. Published: 2026-08-04T20:16:55.883.

Indicators of Compromise (1)

CVE (1)
CVE-2026-70552
Source Attribution

Originally published by NIST NVD on Aug 4, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-70554 — MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti...

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during obje

CVE-2026-70554
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-70553 — MaxSite CMS contains a remote code execution vulnerability that allows unauthent...

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/databa

CVE-2026-70553
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-18810 — A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an ...

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.

CVE-2026-18810
NIST NVD