CVE-2026-87930: MaxSite CMS through 109.6 PHP Object Injection via ci_session

Published Sep 9, 2026
·
Updated

MaxSite CMS through 109.6 passes the cisession cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.

Affected Software

1 affected component
MaxSite CMS MaxSite CMS<=109.6

Event History

Sep 9, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker does not need authentication or user interaction. Exploitation requires forging a valid ci_session cookie with the hardcoded encryption key and a usable PHP object gadget chain that invokes dangerous magic methods.

2

Are default deployments exposed?

The affected behavior is the use of a hardcoded encryption key and unrestricted unserialize() processing of the ci_session cookie. Deployments running MaxSite CMS through 109.6 should be treated as exposed where this session handling is present.

3

What is the impact if a suitable gadget chain exists?

A forged session cookie can inject PHP objects and trigger magic methods. This may corrupt application state or lead to code execution, depending on the classes available in the application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203