What is CVE-2026-70552?
MaxSite CMS versions 109.5 and earlier contain an authentication bypass vulnerability in the AJAX dispatcher. By supplying any X-Requested-With header and requesting a base64-encoded path to any *-ajax.php file, an unauthenticated attacker can gain unauthorized access to admin-protected endpoints. Users should update to the latest version immediately to mitigate this issue.
Azərbaycanca: MaxSite CMS-in 109.5 və daha əvvəlki versiyalarında, AJAX dispetçerində autentifikasiyadan yan keçmə zəifliyi aşkarlanıb. Təcavüzkar istənilən 'X-Requested-With' başlığını təqdim edərək və bazaya kodlanmış yol ilə *-ajax.php fayllarına sorğu göndərərək, admin tərəfindən qorunan funksiyalara icazəsiz giriş əldə edə bilər. Bu boşluğu aradan qaldırmaq üçün istifadəçilərə CMS-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of MaxSite CMS are affected by CVE-2026-70552?
This vulnerability affects MaxSite CMS versions 109.5 and earlier.
How can an attacker gain unauthorized access by exploiting CVE-2026-70552?
An attacker can gain unauthorized access by supplying any X-Requested-With header and requesting a base64-encoded path to a *-ajax.php file to the AJAX dispatcher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.