Remote Code Execution Vulnerability in Concrete CMS by Concrete5
CVE-2026-8135
8.9HIGH
What is CVE-2026-8135?
Concrete CMS versions 9.5.0 and earlier are susceptible to a vulnerability allowing remote code execution due to insecure deserialization in the ExpressEntryList block controller. An attacker with admin privileges can exploit this by bypassing standard protection mechanisms. Through the use of the REST API, an attacker can manipulate data inputs, enabling the insertion of malicious serialized payloads into the block's database. This poses a significant security risk as these payloads are executed when accessed by an administrator, potentially leading to full server control.
Affected Version(s)
Concrete CMS 5.0 <= 9.5.0
