CSRF Vulnerability in Concrete CMS by Concrete5
CVE-2026-2994

2.3LOW

Key Information:

Vendor
CVE Published:
4 March 2026

What is CVE-2026-2994?

Concrete CMS versions below 9.4.8 are vulnerable to a Cross-Site Request Forgery attack that can be exploited by a Rogue Administrator through the Anti-Spam Allowlist Group Configuration. This vulnerability occurs because changes are saved prior to validating the CSRF token associated with the request, which may allow unauthorized modifications to be made without proper verification. The Concrete CMS security team has documented this issue, highlighting that the group_id parameter is the vector for exploitation.

Affected Version(s)

Concrete CMS 5

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

z3rco
.