CVE 9.4 CRITICAL

Authenticated Remote Code Execution via File Overwrite_CVE-2026-46399

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attacker can exploit this vulnerability to configure malicious Git filter commands and achieve code execution on the HAX CMS server. Version 26.0.0 patches the issue.

AI Analysis

Authenticated file overwrite vulnerability allowing code execution on the HAX CMS server

Basic Information

ID CVE-2026-46399
Source GitHub_M
Published Jun 5, 2026 at 18:13

Affected Product

Vendor haxtheweb
Product haxcms-nodejs
Version < 26.0.0
Affected Versions haxtheweb haxcms-nodejs < 26.0.0
haxtheweb haxcms-php < 26.0.0

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor haxtheweb
Product HAX CMS
Version < 26.0.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.