Junglewise Threat Intelligence

CVE-2026-46399: haxtheweb HAX CMS authenticated RCE via file overwrite in saveOutline

CVE-2026-46399 · Severity: info · CVSS 9.4 · Published 2026-06-05

Technologies: Haxtheweb HAX CMS. Vendors: Haxtheweb.

Executive brief

HAX CMS is a content management system used to build and manage microsites. A security flaw in the PHP version of the software allows an authenticated user to overwrite critical system files. By modifying internal configuration files, an attacker can take full control of the server, potentially leading to the theft of customer data, website defacement, or a total service outage.

Technical details

The 'saveOutline' function in the PHP backend of HAX CMS fails to properly restrict the 'location' parameter, allowing it to target files within the site directory, including the '.git' folder. While the application attempts to strip path traversal sequences (../), it does not prevent writing to sensitive subdirectories already present in the relative root. An authenticated attacker can exploit this by overwriting '.git/config' to define a malicious Git filter. Because 'saveOutline' automatically triggers a Git commit, the malicious filter command is executed immediately on the server. This results in full remote code execution (RCE) with the privileges of the web server user. The issue is resolved in version 26.0.0.

Affected products

  • haxtheweb HAX CMS (PHP version) < 26.0.0

Timeline

  • 2026-05-12: advisory: Vendor advisory published via GitHub
  • 2026-06-05: disclosed: CVE published to NVD

References

Related threats