CVE-2026-93364
Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can submit reserved fields such as type and username through the Pages::edit() function in bl-kernel/pages.class.php, which iterates all fields declared in dbFields without per-field authorization, enabling an Author to convert pages to static site-wide navigation entries or transfer page ownership to arbitrary accounts.
| CWE | CWE-915 |
| Vendor | bludit |
| Product | bludit cms |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for bludit bludit cms
Be the first to know when new medium vulnerabilities affecting bludit bludit cms are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
Bludit / Bludit CMS
0 ≤ 3.22.0 0 ≤ 4.0.0-beta-1 0 ≤ 074773eff34b91c002ab9d99029a3edca4934bf1
References
Credits
Akıner Kısa (`akinerkisa`)