CSRF Vulnerability in Concrete CMS by Concrete5
CVE-2026-2994
2.3LOW
What is CVE-2026-2994?
Concrete CMS versions below 9.4.8 are vulnerable to a Cross-Site Request Forgery attack that can be exploited by a Rogue Administrator through the Anti-Spam Allowlist Group Configuration. This vulnerability occurs because changes are saved prior to validating the CSRF token associated with the request, which may allow unauthorized modifications to be made without proper verification. The Concrete CMS security team has documented this issue, highlighting that the group_id parameter is the vector for exploitation.
Affected Version(s)
Concrete CMS 5
