CVE-2026-70554: Deserialization of Untrusted Data in MaxSite MaxSite CMS
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.
AI Analysis
Technical Summary
CVE-2026-70554 is a critical deserialization of untrusted data vulnerability in MaxSite CMS 0.78. The flaw occurs when the application unserializes attacker-controlled serialized PHP objects from the maxsite_comuser cookie without validation or class allowlisting. This allows unauthenticated attackers to craft malicious serialized payloads that trigger PHP magic methods during object reconstruction, enabling property-oriented programming attacks or remote code execution through gadget chains targeting extensions like SoapClient or Imagick. The vulnerability has a CVSS 4.0 score of 9.3, indicating high exploitability and impact.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the server running MaxSite CMS 0.78. This can lead to full system compromise, data theft, or service disruption. The vulnerability does not require user interaction or privileges, making it highly severe.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to block or sanitize the maxsite_comuser cookie input to prevent unserialization of attacker-controlled data. Avoid using unserialize() on untrusted data or implement strict class allowlisting and input validation.
CVE-2026-70554: Deserialization of Untrusted Data in MaxSite MaxSite CMS
Description
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.
CVSS v4.0
Score 9.3critical
Affected software
MaxSite
MaxSite CMS
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-70554 is a critical deserialization of untrusted data vulnerability in MaxSite CMS 0.78. The flaw occurs when the application unserializes attacker-controlled serialized PHP objects from the maxsite_comuser cookie without validation or class allowlisting. This allows unauthenticated attackers to craft malicious serialized payloads that trigger PHP magic methods during object reconstruction, enabling property-oriented programming attacks or remote code execution through gadget chains targeting extensions like SoapClient or Imagick. The vulnerability has a CVSS 4.0 score of 9.3, indicating high exploitability and impact.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the server running MaxSite CMS 0.78. This can lead to full system compromise, data theft, or service disruption. The vulnerability does not require user interaction or privileges, making it highly severe.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to block or sanitize the maxsite_comuser cookie input to prevent unserialization of attacker-controlled data. Avoid using unserialize() on untrusted data or implement strict class allowlisting and input validation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-04T19:19:05.906Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a724e99bf8831d5396be705
Added to database: 08/04/2026, 20:42:01 UTC
Last enriched: 08/12/2026, 15:50:55 UTC
Last updated: 09/19/2026, 10:01:33 UTC
Views: 195
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.