CVE-2026-87930

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 17:17

Updated : 2026-09-09 20:14


NVD link : CVE-2026-87930

Mitre link : CVE-2026-87930

CVE.ORG link : CVE-2026-87930


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data