Executive brief
HAX CMS, a platform for managing microsites, contains a critical security flaw in its Node.js backend that allows anyone to take full control of the system. Due to a coding error, the system's master private security key is accidentally included in publicly accessible data. An attacker can use this key to create fake administrator credentials, allowing them to modify or delete content, upload files, and bypass all security settings without needing a password.
Technical details
The `hmacBase64()` function in the HAXcms Node.js backend suffers from two critical implementation flaws: it uses a hardcoded HMAC key ("0") and appends the actual system private key and salt directly to the output buffer before Base64 encoding. Because the `/system/api/connectionSettings` endpoint is unauthenticated and returns tokens generated by this function, an attacker can perform a single GET request to retrieve the tokens, decode them, and extract the plaintext private key. With this key, the attacker can forge valid JWTs for any user, including the 'admin' account, to gain full administrative access to the CMS. This issue only affects the Node.js implementation; the PHP backend is not vulnerable. The vulnerability is resolved in version 26.0.0.
Affected products
- HAXtheWeb HAXcms Node.js backend < 26.0.0
Timeline
- 2026-05-12: advisory: Original GitHub security advisory published
- 2026-06-05: disclosed: NVD publication date