CVE-2026-70554: Deserialization of Untrusted Data in MaxSite MaxSite CMS
MaxSite CMS version 0.78 contains a critical PHP object injection vulnerability. This flaw allows unauthenticated attackers to execute arbitrary code by sending malicious serialized data in the maxsite_comuser cookie, which is unserialized without validation. The vulnerability enables exploitation via crafted payloads that trigger PHP magic methods during object reconstruction, potentially leading to remote code execution through gadget chains such as SoapClient or Imagick.
AI Analysis
Technical Summary
CVE-2026-70554 is a PHP object injection vulnerability in MaxSite CMS version 0.78. The application unserializes attacker-controlled serialized data from the maxsite_comuser cookie without validation or class allowlisting. This allows unauthenticated attackers to craft malicious serialized PHP objects that trigger magic methods during deserialization, enabling property-oriented programming attacks or remote code execution using gadget chains like those involving SoapClient or Imagick extensions. The vulnerability has a CVSS 4.0 base score of 9.3, indicating critical severity. No official patch or remediation guidance is currently available from the vendor.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the affected system. This can lead to full system compromise, data theft, or service disruption. The vulnerability is critical due to its ease of exploitation (no authentication required) and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, it is recommended to restrict access to the vulnerable application, implement web application firewall (WAF) rules to detect and block malicious serialized payloads, and monitor for suspicious activity related to the maxsite_comuser cookie. Avoid using the affected version 0.78 in production environments.
CVE-2026-70554: Deserialization of Untrusted Data in MaxSite MaxSite CMS
Description
MaxSite CMS version 0.78 contains a critical PHP object injection vulnerability. This flaw allows unauthenticated attackers to execute arbitrary code by sending malicious serialized data in the maxsite_comuser cookie, which is unserialized without validation. The vulnerability enables exploitation via crafted payloads that trigger PHP magic methods during object reconstruction, potentially leading to remote code execution through gadget chains such as SoapClient or Imagick.
CVSS v4.0
Score 9.3critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-70554 is a PHP object injection vulnerability in MaxSite CMS version 0.78. The application unserializes attacker-controlled serialized data from the maxsite_comuser cookie without validation or class allowlisting. This allows unauthenticated attackers to craft malicious serialized PHP objects that trigger magic methods during deserialization, enabling property-oriented programming attacks or remote code execution using gadget chains like those involving SoapClient or Imagick extensions. The vulnerability has a CVSS 4.0 base score of 9.3, indicating critical severity. No official patch or remediation guidance is currently available from the vendor.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the affected system. This can lead to full system compromise, data theft, or service disruption. The vulnerability is critical due to its ease of exploitation (no authentication required) and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, it is recommended to restrict access to the vulnerable application, implement web application firewall (WAF) rules to detect and block malicious serialized payloads, and monitor for suspicious activity related to the maxsite_comuser cookie. Avoid using the affected version 0.78 in production environments.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-04T19:19:05.906Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a724e99bf8831d5396be705
Added to database: 08/04/2026, 20:42:01 UTC
Last enriched: 08/04/2026, 20:56:07 UTC
Last updated: 08/05/2026, 03:53:10 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.