CVE-2026-87927
nicheUnauthenticated Local File Inclusion in MaxSite CMS through 109.6
MaxSite CMS versions through 109.6 contain a local file inclusion flaw (CWE-98) in the ajax and require-maxsite dispatchers. An unauthenticated remote attacker can supply base64-encoded path traversal sequences that bypass the dispatchers' path validation checks, causing the application to include and execute handler files that are otherwise gated behind administrator privileges. Successful exploitation lets the attacker trigger privileged handler actions without any credentials, with the CVSS 4.0 vector indicating a high integrity impact alongside a low confidentiality impact. Any deployment running MaxSite CMS 109.6 or earlier is affected. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Upgrade MaxSite CMS to the latest release as soon as a patched version beyond 109.6 is published. As interim mitigation, restrict or monitor access to the ajax and require-maxsite dispatcher endpoints and block requests containing base64-encoded path traversal payloads via WAF rules. Check web server logs for unauthenticated requests to those dispatchers containing encoded traversal sequences, which may indicate exploitation attempts.
| MaxSite CMS | through 109.6 (all versions up to and including 109.6) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.
- Weakness
- CWE-98
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.