{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/maxsite-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:maxsite:maxsite_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-87929"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MaxSite CMS (\u003c= 109.6)"],"_cs_severities":["critical"],"_cs_tags":["web","cve","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["MaxSite CMS"],"content_html":"\u003cp\u003eMaxSite CMS versions up to and including 109.6 are vulnerable to an authentication bypass due to a hardcoded session encryption key stored in the application/config/config.php file. Because this key remains static across all installations, an unauthenticated remote attacker can reconstruct the session cookie structure. By computing an HMAC-SHA1 signature using the discovered key, an attacker can generate a forged 'ci_session' cookie that grants administrator privileges. This flaw effectively bypasses critical authentication and authorization checks within the application's core functions, specifically is_login() and mso_check_allow(). This vulnerability presents a critical risk as it allows full unauthorized control of the CMS administrative interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain full administrative access to the MaxSite CMS instance. This can lead to complete site takeover, unauthorized access to user data, modification of content, or the injection of malicious code into the web environment. The scope of targeting includes all public-facing instances of MaxSite CMS version 109.6 and below.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade MaxSite CMS to the latest version that remediates CVE-2026-87929.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous session cookie patterns, specifically 'ci_session' tokens that differ in structure or origin from established baseline traffic.\u003c/li\u003e\n\u003cli\u003eAudit the 'application/config/config.php' file on all deployed instances to verify if a unique, site-specific encryption key has been configured, overriding the default.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T19:01:33Z","date_published":"2026-09-09T19:01:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-maxsite-hardcoded-key/","summary":"MaxSite CMS versions 109.6 and earlier contain a hardcoded encryption key in application/config/config.php, enabling unauthenticated attackers to forge administrator session cookies.","title":"Hardcoded Session Encryption Key in MaxSite CMS","url":"https://feed.craftedsignal.io/briefs/2026-09-maxsite-hardcoded-key/"}],"language":"en","title":"CraftedSignal Threat Feed - MaxSite CMS","version":"https://jsonfeed.org/version/1.1"}