PT-2026-47041 · Hax Cms · Hax Cms

CVE-2026-46401

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HAX CMS versions prior to 26.0.0
Description An improper session termination issue exists where authentication tokens remain valid after a user logs out. This allows an attacker who possesses a valid token to maintain persistent access to authenticated CMS functionality, bypassing the session termination mechanism to gain unauthorized access to administrative functions and CMS metadata.
Recommendations Update to version 26.0.0.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46401

Affected Products

Hax Cms