Ad

CVE-2026-35185

HIGH CVSS 4.0: 8.7 EPSS 0.07%
Updated Apr 07, 2026
Node.Js
Parameter Value
CVSS 8.7 (HIGH)
Fixed In 25.0.0
Type CWE-284 (Improper Access Control), CWE-532, CWE-522 (Insufficiently Protected Credentials)
Vendor Node.Js
Public PoC No

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure information.

This vulnerability is fixed in 25.0.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0