🔐 CVE Alert

CVE-2026-93364

MEDIUM 4.3

Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can submit reserved fields such as type and username through the Pages::edit() function in bl-kernel/pages.class.php, which iterates all fields declared in dbFields without per-field authorization, enabling an Author to convert pages to static site-wide navigation entries or transfer page ownership to arbitrary accounts.

CWE CWE-915
Vendor bludit
Product bludit cms
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for bludit bludit cms

Be the first to know when new medium vulnerabilities affecting bludit bludit cms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Bludit / Bludit CMS
0 ≤ 3.22.0 0 ≤ 4.0.0-beta-1 0 ≤ 074773eff34b91c002ab9d99029a3edca4934bf1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
gist.github.com: https://gist.github.com/akinerkisa/6a7532442795beefd29b9c55a100eb16 vulncheck.com: https://www.vulncheck.com/advisories/bludit-cms-mass-assignment-privilege-escalation-via-pages-edit

Credits

Akıner Kısa (`akinerkisa`)