CVE-2026-70552
MaxSite · MaxSite CMS
MaxSite CMS contains an authentication bypass flaw in the AJAX dispatcher, allowing unauthenticated attackers to invoke privileged administrative functions via crafted requests.
Executive summary
A critical authentication bypass in MaxSite CMS allows unauthenticated remote attackers to execute privileged administrative operations and manipulate system data.
Vulnerability
The AJAX dispatcher fails to perform adequate authentication checks when processing requests, enabling unauthenticated users to access admin-gated endpoints. By manipulating headers and paths, attackers can trigger sensitive operations across the plugin ecosystem.
Business impact
The ability to perform administrative actions without authentication poses a severe risk to system integrity and data confidentiality. With a CVSS score of 9.8, the potential for unauthorized modification of polls, votes, and other critical settings necessitates immediate remediation to avoid business logic manipulation and potential service disruption.
Remediation
Immediate Action: Upgrade MaxSite CMS to version 109.6 or later immediately to resolve the authentication bypass vulnerability.
Proactive Monitoring: Monitor server logs for unusual AJAX requests or attempts to access administrative PHP files from unauthorized sources.
Compensating Controls: Deploy a Web Application Firewall to filter requests that contain suspicious X-Requested-With headers or attempt to access restricted AJAX endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations running MaxSite CMS must upgrade to version 109.6 immediately. This update is essential to close the security gap in the AJAX dispatcher and prevent unauthorized administrative access to the platform.