Cross-Site Request Forgery Vulnerability in Concrete CMS by Concrete5
CVE-2026-68532

2.3LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-68532?

A security vulnerability in Concrete CMS allows an unauthenticated remote attacker to manipulate authenticated users with group type management permissions, enabling them to delete custom group types without their consent due to improper CSRF token validation in the dashboard group type controller. This flaw emphasizes the importance of secure token implementation in web applications to safeguard user actions.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.