HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access. Version 26.0.0 contains a fix.
CVSS
No CVSS.
References
Configurations
No configuration.
History
08 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/haxtheweb/issues/security/advisories/GHSA-q862-gcgq-5m6g - |
05 Jun 2026, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-05 19:16
Updated : 2026-06-17 10:53
NVD link : CVE-2026-46393
Mitre link : CVE-2026-46393
CVE.ORG link : CVE-2026-46393
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
