Unrated severityNVD Advisory· Published Aug 4, 2026
MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie
CVE-2026-70554
Description
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- max-3000.com/page/maxsite-cms-109-6mitrepatch
- www.vulncheck.com/advisories/maxsite-cms-unauthenticated-php-object-injection-via-maxsite-comuser-cookiemitrethird-party-advisory
News mentions
0No linked articles in our index yet.