Cross Site Request Forgery Vulnerability in Concrete CMS by Concrete Solutions
CVE-2026-8412

2.3LOW

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8412?

Concrete CMS versions prior to 9.5.0 are susceptible to a Cross Site Request Forgery (CSRF) vulnerability found in the bulk cache controller. This flaw allows attackers to potentially trick authenticated users into executing unwanted actions on behalf of the user, jeopardizing the integrity of user data and the application's secure operation. The Concrete CMS security team has acknowledged this issue, which highlights the importance of timely updates to maintain robust security practices.

Affected Version(s)

Concrete CMS 9.0 <= 9.5.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yonatan Drori (Tenzai)
.