CRITICAL 9.8 CVE-2026-87929 Published 9 Sept 2026

MaxSite CMS Admin Session Cookie Forgery

Worried this affects one of your servers?

MaxSite CMS versions up to 109.6 are affected by a hardcoded session encryption key in application/config/config.php.

This key is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies.

Attackers can compute an HMAC-SHA1 using the publicly known encryption key to create a malicious ci_session cookie with administrator privileges, bypassing authentication checks.

Reference: CVE-2026-87929 on NVD

← Back to Security News