MaxSite CMS <=109.6 Vulnerability: Critical Session Key Issue
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- maxsite cms (other)
- Patched version
- Not yet available
MaxSite CMS through version 109.6 reportedly has a hardcoded session encryption key vulnerability, allowing potential unauthenticated attacks.
What happened
MaxSite CMS through version 109.6 is under investigation for a critical vulnerability. The issue involves a hardcoded session encryption key in the application/config/config.php file, which is not altered during installation. This flaw allows unauthenticated attackers to potentially forge administrator session cookies, leading to unauthorized access. The vulnerability has been assigned CVE-2026-87929 with a CVSS score of 9.8, indicating a critical severity level.
The vulnerability was first flagged on 2026-09-09T17:17:53.840000+00:00. There are no reports of this vulnerability being exploited in the wild at this time. Users of MaxSite CMS versions up to and including 109.6 should assess their exposure and take immediate action to mitigate the risk.
What to do about it
- Check your MaxSite CMS version to determine if it is <=109.6.
- If you are using a version <=109.6, upgrade to a version that addresses the hardcoded session encryption key issue.
- Monitor the NVD and other primary sources for updates on a patched version.
- In the absence of an official fix, consider implementing additional security measures to protect your session management.
- Regularly review your CMS configurations for any security-related changes or updates.
How 0Day would have caught this
maxsite cms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using MaxSite CMS version 109.6 or earlier, you are potentially affected by this vulnerability.
What should I do right now?
Immediately check your MaxSite CMS version and upgrade if you are using version 109.6 or earlier. Monitor primary sources for updates on a fix.
Is there a patched version available?
No official fix has been published yet. Monitor the sources for updates.
How severe is this vulnerability?
The vulnerability has a CVSS score of 9.8, indicating a critical severity level.