CVE-2026-87927: MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher
Published Sep 9, 2026
·Updated
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.
Affected Software
1 affected component
Maxsite MaxSite CMS<=109.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MaxSite CMSto a version that resolves this vulnerability.Fixed in 109.6 - Compensating control
Block unauthenticated access to the MaxSite CMS ajax/require-maxsite dispatcher endpoints and restrict them to authenticated/authorized users while patching.
Event History
Sep 9, 2026
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionSeverityWeakness