CVE-2026-87927
Deferred Deferred - Pending Action

Path Traversal in MaxSite CMS

Vulnerability report for CVE-2026-87927, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
maxsite maxsite_cms *
maxsite maxsite_cms From 0.78 (inc) to 109.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-98 The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local file inclusion vulnerability in MaxSite CMS versions up to 109.6. It exists in the ajax and require-maxsite dispatchers where unauthenticated attackers can execute privileged handler files by providing base64-encoded path traversal sequences. The flaw allows bypassing path validation checks to run admin-gated handler actions without authentication, gaining access to sensitive functionality.

Detection Guidance

To detect this vulnerability, inspect network traffic for requests to ajax.php or require-maxsite.php with base64-encoded path traversal sequences in the URI. Check server logs for unusual file inclusion attempts or unauthorized access to privileged handler files. Use tools like Wireshark or tcpdump to capture and analyze HTTP requests containing base64 strings with ../ sequences.

Impact Analysis

An attacker could exploit this to include and execute arbitrary PHP files on the server, potentially leading to remote code execution if writable files are targeted. Even without direct code execution, sensitive admin functionality could be accessed, compromising the entire CMS installation and its data.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection standards like GDPR and HIPAA by enabling unauthorized access to sensitive data and administrative functions. It could lead to data breaches, unauthorized modifications, and loss of control over protected information.

Mitigation Strategies

Immediately update MaxSite CMS to the latest patched version. If no patch is available, disable the ajax and require-maxsite dispatchers in the web server configuration. Implement strict input validation to reject base64-encoded strings containing path traversal sequences like ../. Restrict file inclusion to an explicit allowlist of permitted handler files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87927. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart