CRITICAL
9.8 CVE-2026-87929 Published 9 Sept 2026
MaxSite CMS Admin Session Cookie Forgery
Worried this affects one of your servers?
MaxSite CMS versions up to 109.6 are affected by a hardcoded session encryption key in application/config/config.php.
This key is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies.
Attackers can compute an HMAC-SHA1 using the publicly known encryption key to create a malicious ci_session cookie with administrator privileges, bypassing authentication checks.
Reference: CVE-2026-87929 on NVD
← Back to Security News