PHP · SEPTEMBER 2026 · EARLY WARNING

MaxSite CMS <=109.6 Vulnerability: Critical Session Key Issue

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
maxsite cms (other)
Patched version
Not yet available
CVE-2026-87929

MaxSite CMS through version 109.6 reportedly has a hardcoded session encryption key vulnerability, allowing potential unauthenticated attacks.

What happened

MaxSite CMS through version 109.6 is under investigation for a critical vulnerability. The issue involves a hardcoded session encryption key in the application/config/config.php file, which is not altered during installation. This flaw allows unauthenticated attackers to potentially forge administrator session cookies, leading to unauthorized access. The vulnerability has been assigned CVE-2026-87929 with a CVSS score of 9.8, indicating a critical severity level.

The vulnerability was first flagged on 2026-09-09T17:17:53.840000+00:00. There are no reports of this vulnerability being exploited in the wild at this time. Users of MaxSite CMS versions up to and including 109.6 should assess their exposure and take immediate action to mitigate the risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If maxsite cms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using MaxSite CMS version 109.6 or earlier, you are potentially affected by this vulnerability.

What should I do right now?

Immediately check your MaxSite CMS version and upgrade if you are using version 109.6 or earlier. Monitor primary sources for updates on a fix.

Is there a patched version available?

No official fix has been published yet. Monitor the sources for updates.

How severe is this vulnerability?

The vulnerability has a CVSS score of 9.8, indicating a critical severity level.

Sources

Join the 0Day waitlist →

← Back to all threats