CVE-2026-46395 affects the HAX CMS Node.js backend prior to version 26.0.0. The vulnerability is in the hmacBase64() function, which contains two cryptographic implementation flaws. First, it uses the literal string "0" as the HMAC key instead of the supplied key material, causing identical HMAC output across installations for the same input. Second, after computing the HMAC, it appends the real secret key material (this.privateKey + this.salt) directly to the HMAC output before base64-encoding and returning it. As a result, any token generated by this function embeds the application's signing secret. The unauthenticated /system/api/connectionSettings endpoint returns tokens generated by this function, allowing an attacker to retrieve a token, base64-decode it, discard the first 32 bytes of HMAC output, and recover the private signing key and salt. With the recovered secret, an attacker can forge arbitrary admin-level JWTs and other signed tokens. The issue is specific to the Node.js backend; the PHP backend reportedly implements the function correctly and returns only the hash. Version 26.0.0 fixes the flawed implementation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/system/api/connectionSettings, place the vulnerable Node.js backend behind compensating access controls, and limit network exposure to trusted users or administrative paths only. Rotate privateKey and salt, invalidate existing tokens, and monitor for suspicious token-based administrative actions, especially privileged operations occurring without normal authentication events.Patch, then assume compromise.
@haxtheweb/haxcms-nodejs to version 26.0.0 or later, which corrects the hmacBase64() implementation. Because the signing secret may already have been exposed, rotate both the private signing key and salt after patching, and invalidate all previously issued JWTs and other tokens derived from the compromised secret. Verify that unauthenticated endpoints do not expose newly generated signed tokens after remediation.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone JavaScript PoC for CVE-2026-46395 affecting the HAXcms Node.js backend. It contains 5 files total: metadata/support files (.gitignore, LICENSE, package.json), a detailed README, and one main exploit script, poc_hmac_key_leak.js. The codebase is primarily JavaScript and is not part of a larger exploit framework. The exploit targets a broken HMAC implementation in HAXcms's Node.js backend (haxcms-nodejs/src/lib/HAXCMS.js). According to the included analysis, the vulnerable hmacBase64() function incorrectly computes HMAC-SHA256 using a hardcoded key "0" and then appends the real secret (privateKey + salt) directly into the returned base64url token. Because /system/api/connectionSettings is unauthenticated, an attacker can issue a single GET request, obtain one of these malformed tokens, base64-decode it, discard the first 32 bytes, and recover the signing secret in plaintext. The PoC script operationalizes the full attack chain. It accepts a target URL argument, defaults to http://localhost:3000, and uses Node's http/https modules to fetch the unauthenticated endpoint. It includes helper routines to reproduce both the vulnerable and correct HMAC behavior, extract the embedded key from a token, and send POST requests. Based on the README and visible code, the script then verifies the extracted key, forges an admin JWT using jsonwebtoken when available, forges additional request tokens, and calls an authenticated API action to demonstrate write access by creating a site. This makes it more than a detector: it is an operational exploit PoC with a concrete post-exploitation action. Fingerprintable targets and observables are limited and mostly local/example values: the default target http://localhost:3000, the unauthenticated endpoint /system/api/connectionSettings, references to vulnerable source paths (src/lib/HAXCMS.js, src/app.js), and the _sites/ directory mentioned as evidence of successful site creation. No hardcoded external C2, IPs, or exfiltration infrastructure are present. Overall, the repository's purpose is to demonstrate and validate unauthorized compromise of vulnerable HAXcms Node.js instances by extracting the server signing secret and forging trusted authentication artifacts, culminating in admin-level API access.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.