CVE-2026-87930
Deferred Deferred - Pending Action

MaxSite CMS PHP Object Injection Vulnerability

Vulnerability report for CVE-2026-87930, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
maxsite maxsite_cms *
maxsite maxsite_cms From 0.78 (inc) to 109.6 (inc)
codeigniter codeigniter *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87930 is a PHP Object Injection vulnerability in MaxSite CMS through version 109.6. The flaw occurs because the application deserializes untrusted data from the ci_session cookie without proper class restrictions. Attackers can forge malicious session cookies using a hardcoded encryption key to inject PHP objects, triggering magic methods that corrupt application state or potentially execute arbitrary code if exploitable gadget classes exist.

Detection Guidance

Check for unsafe unserialize() calls in MaxSite CMS files like application/maxsite/common/core/options.php, application/maxsite/common/core/security.php, system/libraries/Session.php, and application/maxsite/plugins/rss_get/lastrss.php. Inspect the ci_session cookie for serialized objects and monitor for unexpected session behavior or application corruption.

Impact Analysis

This vulnerability allows unauthenticated attackers to corrupt application logic, modify options, alter group permissions, or achieve remote code execution if a suitable PHP gadget chain exists. Attackers can forge session cookies to bypass authentication or manipulate application state without credentials.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information. Unauthorized code execution or data corruption risks non-compliance with these regulations due to potential breaches of confidentiality and integrity.

Mitigation Strategies

Replace all unsafe unserialize() calls with unserialize($data, ['allowed_classes' => false]). Avoid storing objects in client-controlled session cookies. Use json_decode() and json_encode() for application data. Ensure server-side sessions are enabled and revalidate user data from the database instead of cookies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87930. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart