Junglewise Threat Intelligence

CVE-2026-46401: haxtheweb HAX CMS insufficient session expiration

CVE-2026-46401 · Severity: info · CVSS 5.3 · Published 2026-06-05

Technologies: Haxtheweb HAX CMS. Vendors: Haxtheweb.

Executive brief

HAX CMS is a content management system used to build and manage microsites. A security flaw in its logout process means that when a user logs out, their session token is not actually deactivated on the server. If an attacker manages to obtain a user's session token, they can continue to access administrative functions and site data even after the legitimate user has ended their session.

Technical details

HAX CMS (specifically the haxcms-php package) fails to implement server-side session invalidation. While the logout function clears the client-side state, the server does not blacklist or revoke the 'user_token' associated with the session. An attacker with access to a previously valid token can replay it against authenticated API endpoints (such as /system/api/getSkeleton or /system/api/getSites) to maintain persistent access. The vulnerability is classified as CWE-613 (Insufficient Session Expiration) and is resolved in version 26.0.0 by implementing proper server-side token revocation.

Affected products

  • haxtheweb HAX CMS (haxcms-php) < 26.0.0

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-06-05: disclosed: NVD publication date
  • 2026-06-05: patched: Version 26.0.0 released to address the issue

References

Related threats