← Back to search

CVE-2026-70554

9.8 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
MaxSite CMS is vulnerable to PHP object injection, allowing unauthenticated attackers to execute arbitrary code via a malicious serialized PHP object in the maxsite_comuser cookie.
Exploitability
Exploitation is relatively straightforward as attackers can craft a payload in a single HTTP request, but requires the attacker to have control over the cookie value.
Blast radius
If exploited, this vulnerability could result in full remote code execution on the affected server, potentially leading to data theft, service disruption, or complete compromise of the system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to the maxsite_comuser cookie to prevent unauthenticated attackers from injecting PHP objects.
rcewebcookiephpunauthenticated

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.