Cross-Site Request Forgery Vulnerability in Concrete CMS by Concrete5
CVE-2026-81907

6.1MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-81907?

Concrete CMS versions up to 9.5.2 are susceptible to a CSRF vulnerability in the Express 'Clear Entries' function. This security flaw allows an attacker to manipulate an authenticated administrator's actions. By exploiting this vulnerability, a remote attacker can force an authenticated user to visit a malicious page, resulting in the permanent deletion of all entries tied to a chosen Express entity. This risk arises because the system fails to enforce checks for valid CSRF tokens in the relevant POST request, leaving room for unauthorized operations. Additionally, the predictable nature of the default Contact Express object’s entity UUID facilitates targeting without requiring direct access to the dashboard.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xwantedxd
.