CVE-2026-87929
Deferred Deferred - Pending Action

Hard-Coded Session Key in MaxSite CMS

Vulnerability report for CVE-2026-87929, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks in is_login() and mso_check_allow() functions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
maxsite maxsite_cms *
maxsite maxsite_cms From 0.78 (inc) to 109.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87929 is an authentication bypass vulnerability in MaxSite CMS versions 0.78 through 109.6. It stems from a hardcoded session encryption key in the application's configuration file that remains unchanged during installation. Attackers can forge administrator session cookies by generating a valid HMAC-SHA1 signature using this known key, bypassing authentication checks in functions like is_login() and mso_check_allow().

Detection Guidance

Check MaxSite CMS configuration files for hardcoded session encryption keys in application/config/config.php. Search for 'encryption_key' values that are static or publicly known. Inspect network traffic for forged ci_session cookies with admin privileges.

Impact Analysis

Unauthenticated attackers can gain full administrator access to the MaxSite CMS without credentials. This allows them to take control of the website, modify content, access sensitive data, install malicious software, or disrupt services. The impact includes complete system compromise and potential data breaches.

Compliance Impact

This vulnerability likely violates compliance requirements for GDPR and HIPAA due to unauthorized access to sensitive data. GDPR mandates strict access controls and breach notification, while HIPAA requires protection of health information. The authentication bypass could lead to unauthorized data exposure, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Replace the hardcoded session encryption key in config.php with a strong, randomly generated key. Enable server-side session management instead of cookie-based sessions. Update to the latest MaxSite CMS version if available. Review and fix database re-validation logic to ensure user data is not derived from cookies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87929. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart