9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attacker can exploit this vulnerability to configure malicious Git filter commands and achieve code execution on the HAX CMS server. Version 26.0.0 patches the issue.
AI Analysis
Authenticated file overwrite vulnerability allowing code execution on the HAX CMS server
Basic Information
ID
CVE-2026-46399
Source
GitHub_M
Published
Jun 5, 2026 at 18:13
Affected Product
Vendor
haxtheweb
Product
haxcms-nodejs
Version
< 26.0.0
Affected Versions
haxtheweb haxcms-nodejs < 26.0.0
haxtheweb haxcms-php < 26.0.0
haxtheweb haxcms-php < 26.0.0
CWE Classification
AI Assessment
AI Score
9.4 / 10
AI Severity
Critical
Vendor
haxtheweb
Product
HAX CMS
Version
< 26.0.0