PT-2026-47039 · Hax Cms · Hax Cms

CVE-2026-46398

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HAX CMS versions 25.0.0 through 25.x
Description The haxcms refresh token cookie is configured without the Secure flag. This configuration allows the cookie to be transmitted over unencrypted HTTP connections, which enables an attacker to steal the token using packet sniffing on the network.
Recommendations Update to version 26.0.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46398

Affected Products

Hax Cms