CVE-2026-46399
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attacker can exploit this vulnerability to configure malicious Git filter commands and achieve code execution on the HAX CMS server. Version 26.0.0 patches the issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.29%
- CWE
- CWE-15, CWE-73, CWE-78
- Published
- 2026-06-05
- Last modified
- 2026-06-08
Affected products
- haxtheweb haxcms-nodejs
- haxtheweb haxcms-php
Weakness type
Related vulnerabilities
- CVE-2026-19592 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS...
- CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree...
- CVE-2026-16708 — IBM Db2 Mirror for i is affected by multiple vulnerabilities
- CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control...
- CVE-2026-73661 — FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
- CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)
- CVE-2026-56567 — HCL iControl is affected by multiple security vulnerabilities.
- CVE-2026-46485 — Dash: Users can write to config despire permissions (OIDC tested)