Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks in is_login() and mso_check_allow() functions. | |
| Title | MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key | |
| First Time appeared |
Max-3000
Max-3000 maxsite Cms |
|
| Weaknesses | CWE-321 | |
| CPEs | cpe:2.3:a:max-3000:maxsite_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Max-3000
Max-3000 maxsite Cms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T16:45:00.096Z
Reserved: 2026-09-09T16:12:31.422Z
Link: CVE-2026-87929
No data.
Status : Received
Published: 2026-09-09T17:17:53.840
Modified: 2026-09-09T17:17:53.840
Link: CVE-2026-87929
No data.
OpenCVE Enrichment
Updated: 2026-09-09T19:00:15Z