CVE-2026-70552 Details
Description
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.
An authentication bypass vulnerability has been identified in MaxSite CMS versions through 109.5. This vulnerability resides in the AJAX dispatcher, allowing unauthenticated attackers to access admin-protected endpoints. Exploitation involves sending a base64-encoded path that resolves to any *-ajax.php file within the codebase, along with an X-Requested-With header. This bypass enables access to privileged plugin endpoints without the need for credentials, potentially allowing attackers to manipulate poll states and vote counts, and to amplify the effects of any harmful actions executed by admin-only AJAX files across the plugin ecosystem.
Users are advised to update to MaxSite CMS version 109.6, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 4, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/maxsite/cms | [email protected] | Source CodeVendor |
| https://max-3000.com/page/maxsite-cms-109-6 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-ajax-dispatcher-bypass-via-ajax-php | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MaxSite CMS | <= 109.5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |
Volerion