PT-2026-67848 · Maxsite · Maxsite Cms
CVE-2026-70554
·
Published
2026-08-04
·
Updated
2026-08-31
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MaxSite CMS (affected versions not specified)
Description
An issue exists where unauthenticated attackers can execute arbitrary code by providing malicious serialized data through the
maxsite comuser cookie. The application passes this data directly to the unserialize() function without proper validation or class allowlisting. This allows for property-oriented programming attacks or remote code execution by triggering magic methods during object graph reconstruction, utilizing gadget chains such as those found in the SoapClient or Imagick extensions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maxsite Cms