PHP Object Injection Vulnerability in Concrete CMS by Concrete5
CVE-2026-10721

8.4HIGH

Key Information:

Vendor
CVE Published:
10 June 2026

What is CVE-2026-10721?

Concrete CMS versions prior to 9.5.2 have a vulnerability that allows for PHP Object Injection through the unserialize() function in the Permission, Cache, and Search components. An unauthenticated attacker can exploit this flaw by injecting a malicious serialized payload into the database, enabling arbitrary PHP object instantiation. This vulnerability poses serious security risks that could be leveraged to execute unauthorized actions within the CMS.

Affected Version(s)

Concrete CMS 5 <= 9.5.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

XananasX7
.