PT-2026-47030 · Hax Cms · Hax Cms

CVE-2026-46394

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HAX CMS versions prior to 26.0.0
Description An OS command injection issue exists in the Git.php library of the PHP backend. The application executes shell command strings using the proc open() function without properly sanitizing input. An attacker capable of controlling parameters passed into Git operations can execute arbitrary OS commands with web server privileges. Of the 17 functions that invoke shell commands, only the commit() function correctly utilizes escapeshellarg(). If combined with a configuration manipulation flaw, this can result in full remote code execution and complete system compromise.
Recommendations Update to version 26.0.0.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46394

Affected Products

Hax Cms