PT-2026-67848 · Maxsite · Maxsite Cms

CVE-2026-70554

·

Published

2026-08-04

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MaxSite CMS (affected versions not specified)
Description An issue exists where unauthenticated attackers can execute arbitrary code by providing malicious serialized data through the maxsite comuser cookie. The application passes this data directly to the unserialize() function without proper validation or class allowlisting. This allows for property-oriented programming attacks or remote code execution by triggering magic methods during object graph reconstruction, utilizing gadget chains such as those found in the SoapClient or Imagick extensions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70554

Affected Products

Maxsite Cms