Junglewise Threat Intelligence

CVE-2026-70552: MaxSite CMS authentication bypass in AJAX dispatcher

CVE-2026-70552 · Severity: critical · CVSS 9.8 · Published 2026-08-04

Technologies: MaxSite CMS.

Executive brief

MaxSite CMS is a content management system used to build websites and blogs. An unauthenticated attacker can bypass authentication on admin-only features by sending specially crafted AJAX requests with a fake header and base64-encoded paths, allowing them to manipulate website data, modify poll votes, and invoke any dangerous operations normally restricted to administrators without needing valid credentials.

Technical details

The vulnerability is an authentication bypass affecting the AJAX dispatcher in MaxSite CMS version 109.5 and earlier. An attacker can supply any X-Requested-With header and request a base64-encoded path resolving to any *-ajax.php file to reach privileged plugin endpoints without authentication. The flaw allows unauthenticated remote access to admin-gated endpoints, enabling manipulation of poll states and vote counts, and exploitation of any dangerous operations performed by admin-only AJAX files. The vulnerability was patched in version 109.6, released 2026-03-16, and an exploit was publicly disclosed prior to patching (discovered January-February 2026).

Affected products

  • MaxSite CMS 109.5 and earlier

Timeline

  • 2026-01: disclosed: Vulnerability discovered and reported January-February 2026
  • 2026-03-16: patched: Fixed in MaxSite CMS 109.6 (security update released 2026-03-16)
  • 2026-08-04: exploited: Exploit publicly disclosed before CVE publication; CVE-2026-70552 published 2026-08-04
  • 2026-08-04: advisory: CVE-2026-70552 published

References