Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can submit reserved fields such as type and username through the Pages::edit() function in bl-kernel/pages.class.php, which iterates all fields declared in dbFields without per-field authorization, enabling an Author to convert pages to static site-wide navigation entries or transfer page ownership to arbitrary accounts.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-915"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93364.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "4.0.0-beta-1"
},
{
"last_affected": "074773eff34b91c002ab9d99029a3edca4934bf1"
}
],
"source": "AFFECTED_FIELD"
}
]
}