PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35185 haxtheweb CVE debrief

CVE-2026-35185 is a sensitive information exposure vulnerability in HAX CMS, a platform used to manage microsite universes with PHP or NodeJs backends. The /server-status endpoint is publicly accessible, exposing sensitive information including authentication tokens, user activity, client IP addresses, and server configuration details. This vulnerability allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure information. The vulnerability is fixed in version 25.0.0. Affected users should be aware of the potential risks and take immediate action to mitigate the vulnerability.

Vendor
haxtheweb
Product
HAXiam
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Users of HAX CMS, particularly those with microsites managed by the platform, should be aware of this vulnerability. Anyone with access to the /server-status endpoint can exploit this issue. Operators, administrators, and security teams responsible for HAX CMS deployments should prioritize mitigation and review system logs for potential exploitation.

Technical summary

The HAX CMS /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure information. The vulnerability is fixed in version 25.0.0. Users should upgrade to the latest version and restrict access to the /server-status endpoint to prevent exploitation.

Defensive priority

High priority due to the sensitive nature of the exposed information and the potential for exploitation by unauthenticated users. Immediate action is required to prevent potential data breaches and unauthorized access.

Recommended defensive actions

  • Upgrade to HAX CMS version 25.0.0 or later
  • Restrict access to the /server-status endpoint
  • Monitor for suspicious activity related to the /server-status endpoint
  • Review and update authentication and authorization mechanisms
  • Perform a thorough review of system logs for potential exploitation
  • Implement additional monitoring for unusual user activity
  • Verify that all affected systems have been updated or mitigated

Evidence notes

The CVE record was published on 2026-04-06T20:16:27.040Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected systems and review official advisories for specific guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T20:16:27.040Z and has not been modified since then. The NVD entry is currently Analyzed.