CRITICALVulnerability

CVE-2026-87929

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks in is_login() and mso_check_allow() functions.

Properties

severity
CRITICAL
score
9.8
cve_id
CVE-2026-87929
signal_observed_at
2026-09-17T21:32:24+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-09-09T17:17:53.840
last_modified
2026-09-14T14:17:18.670

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Use of Hard-coded Cryptographic Key

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-87929 — Ninja Signal Threat Intelligence | Ninja Signal