Back

CRITICAL

MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie

Published Aug 4, 2026

Description

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 4, 2026
Updated Sep 24, 2026
Reserved Aug 4, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Deferred
Modified Aug 31, 2026
Red Hat
Severity n/a
Public date n/a