Junglewise Threat Intelligence

CVE-2026-46493: haxtheweb HAX CMS weak PRNG for salts in install.php

CVE-2026-46493 · Severity: high · CVSS 7.5 · Published 2026-06-05

Technologies: Haxtheweb HAX CMS. Vendors: Haxtheweb.

Executive brief

HAX CMS, a platform for managing microsites, was found to use an insecure method for generating security 'salts' used in data protection. Because these salts are predictable, an attacker could potentially bypass certain security controls to access sensitive information. This issue affects the PHP-based backend of the software and has been resolved in the latest update.

Technical details

HAX CMS (specifically the haxcms-php backend) utilizes the PHP `uniqid()` function to generate salts within its `install.php` component. According to PHP documentation, `uniqid()` does not produce cryptographically secure values and is based on the system time, making the resulting salts predictable. This vulnerability is classified as CWE-338 (Use of Cryptographically Weak PRNG). An unauthenticated remote attacker could exploit this predictability to compromise cryptographic operations that rely on these salts, leading to a loss of confidentiality. The issue has been addressed in version 26.0.1 by migrating to a cryptographically secure pseudo-random number generator (CSPRNG).

Affected products

  • haxtheweb HAX CMS (PHP backend) < 26.0.1

Timeline

  • 2026-05-14: advisory: GitHub Security Advisory GHSA-xg43-xm47-74cp published
  • 2026-06-05: disclosed: CVE-2026-46493 published to NVD
  • 2026-06-05: patched: Version 26.0.1 released

References

Related threats