Junglewise Threat Intelligence

CVE-2026-6411: MAXHUB Pivot hardcoded cryptographic key and DoS vulnerability

CVE-2026-6411 · Severity: high · CVSS 7.3 · Published 2026-05-07

Executive brief

MAXHUB Pivot is a management application used for controlling interactive displays and collaboration hardware. A security flaw allows unauthorized individuals to access sensitive tenant information, such as email addresses, and potentially disrupt operations by flooding the system with unauthorized device registrations. This could lead to data privacy breaches or a total loss of service for the management platform.

Technical details

The MAXHUB Pivot client application (prior to v1.36.2) utilizes a hardcoded AES cryptographic key (CWE-327). An unauthenticated remote attacker can use this key to decrypt tenant email addresses and associated metadata obtained from the system. Additionally, the application's MQTT implementation allows for the unauthorized enrollment of multiple devices into a tenant, which can be leveraged to trigger a denial-of-service (DoS) condition. The vulnerability is remediated in version 1.36.2, which was distributed via an over-the-air (OTA) update.

Affected products

  • MAXHUB Pivot client application prior to v1.36.2

Timeline

  • 2026-05-07: disclosed: Initial publication of ICSA-26-127-01 by CISA.
  • 2026-05-07: patched: Remediation available in version 1.36.2 via OTA update.

References