PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70552 MaxSite CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.883Z and has not been modified since then. The NVD entry is currently Received. CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier, allowing unauthenticated attackers to bypass authentication and access admin-gated endpoints. This vulnerability exists in the AJAX dispatcher, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree. Administrators and users of MaxSite CMS 109.5 and earlier should be aware of this vulnerability and take immediate action to prevent potential exploitation. This vulnerability can be used by attackers to access sensitive areas of the website without authentication, potentially leading to further exploitation and data breaches. Immediate attention is required to prevent potential exploitation. The vendor and product information is not confirmed, with the vendor name listed as Unknown Vendor.

Vendor
MaxSite
Product
MaxSite CMS
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-04
Original CVE updated
2026-08-05
Advisory published
2026-08-04
Advisory updated
2026-08-05

Who should care

Administrators and users of MaxSite CMS 109.5 and earlier should be aware of this vulnerability and take immediate action to prevent potential exploitation. This vulnerability can be used by attackers to access sensitive areas of the website without authentication, potentially leading to further exploitation and data breaches.

Technical summary

CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier. The vulnerability exists in the AJAX dispatcher, allowing unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. This bypass enables actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.

Defensive priority

CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier, allowing unauthenticated attackers to bypass authentication and access admin-gated endpoints. Immediate attention is required to prevent potential exploitation.

Recommended defensive actions

  • Review and apply vendor remediation for MaxSite CMS 109.5 and earlier
  • Implement compensating controls to restrict access to admin-gated endpoints
  • Monitor for suspicious activity related to AJAX dispatcher bypass
  • Perform inventory checks to identify affected systems
  • Exception tracking and retest after remediation

Evidence notes

The CVE record and NVD entry provide information about the vulnerability in MaxSite CMS 109.5 and earlier. The vulnerability allows unauthenticated attackers to bypass authentication and access admin-gated endpoints. The vendor and product information is not confirmed, with the vendor name listed as Unknown Vendor.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.883Z and has not been modified since then.