CVE-2026-70554
9.8 CRITICALpublic exploit availablePublished 2026-08-04 · Updated 2026-08-05
AI risk analysis
- Summary
- MaxSite CMS is vulnerable to PHP object injection, allowing unauthenticated attackers to execute arbitrary code via a malicious serialized PHP object in the maxsite_comuser cookie.
- Exploitability
- Exploitation is relatively straightforward as attackers can craft a payload in a single HTTP request, but requires the attacker to have control over the cookie value.
- Blast radius
- If exploited, this vulnerability could result in full remote code execution on the affected server, potentially leading to data theft, service disruption, or complete compromise of the system.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected feature or restrict access to the maxsite_comuser cookie to prevent unauthenticated attackers from injecting PHP objects.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-82384PoC
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2026-12227
- HIGHCVE-2026-14553
- HIGHCVE-2026-15027
- CRITICALCVE-2026-16618
- CRITICALCVE-2026-39353PoC
- HIGHCVE-2026-60009PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.