CVE-2026-46511

HIGH

HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack

Title source: cna
STIX 2.1

Description

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including the `jwt`, `user_token`, `site_token`, and `appstore_token`) into a global JavaScript variable (`window.appSettings`). An attacker can exploit the XSS vulnerability to force a victim's browser to silently fetch their specific connection settings, extract the tokens, and exfiltrate them to an attacker-controlled webhook. Version 26.0.0 patches the issue.

References (1)

Core 1
Core References

Scores

CVSS v4 8.7
EPSS 0.0027
EPSS Percentile 19.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-522 CWE-79 CWE-922
Status published
Products (3)
haxtheweb/haxcms-nodejs 0 - 26.0.0npm
haxtheweb/haxcms-nodejs < 26.0.0
haxtheweb/haxcms-php < 26.0.0
Published Jun 05, 2026
Tracked Since Jun 06, 2026