PatchSiren cyber security CVE debrief
CVE-2026-70552 MaxSite CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.883Z and has not been modified since then. The NVD entry is currently Received. CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier, allowing unauthenticated attackers to bypass authentication and access admin-gated endpoints. This vulnerability exists in the AJAX dispatcher, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree. Administrators and users of MaxSite CMS 109.5 and earlier should be aware of this vulnerability and take immediate action to prevent potential exploitation. This vulnerability can be used by attackers to access sensitive areas of the website without authentication, potentially leading to further exploitation and data breaches. Immediate attention is required to prevent potential exploitation. The vendor and product information is not confirmed, with the vendor name listed as Unknown Vendor.
- Vendor
- MaxSite
- Product
- MaxSite CMS
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-08-31
Who should care
Administrators and users of MaxSite CMS 109.5 and earlier should be aware of this vulnerability and take immediate action to prevent potential exploitation. This vulnerability can be used by attackers to access sensitive areas of the website without authentication, potentially leading to further exploitation and data breaches.
Technical summary
CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier. The vulnerability exists in the AJAX dispatcher, allowing unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. This bypass enables actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.
Defensive priority
CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier, allowing unauthenticated attackers to bypass authentication and access admin-gated endpoints. Immediate attention is required to prevent potential exploitation.
Recommended defensive actions
- Review and apply vendor remediation for MaxSite CMS 109.5 and earlier
- Implement compensating controls to restrict access to admin-gated endpoints
- Monitor for suspicious activity related to AJAX dispatcher bypass
- Perform inventory checks to identify affected systems
- Exception tracking and retest after remediation
Evidence notes
The CVE record and NVD entry provide information about the vulnerability in MaxSite CMS 109.5 and earlier. The vulnerability allows unauthenticated attackers to bypass authentication and access admin-gated endpoints. The vendor and product information is not confirmed, with the vendor name listed as Unknown Vendor.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70552 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70552
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70552 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70552
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/maxsite/cms
-
Source reference
Unverified legacy reference
URL: https://max-3000.com/page/maxsite-cms-109-6
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/maxsite-cms-unauthenticated-ajax-dispatcher-bypass-via-ajax-php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.