Cross Site Request Forgery Vulnerability in Concrete CMS by Concrete Solutions
CVE-2026-8412
2.3LOW
What is CVE-2026-8412?
Concrete CMS versions prior to 9.5.0 are susceptible to a Cross Site Request Forgery (CSRF) vulnerability found in the bulk cache controller. This flaw allows attackers to potentially trick authenticated users into executing unwanted actions on behalf of the user, jeopardizing the integrity of user data and the application's secure operation. The Concrete CMS security team has acknowledged this issue, which highlights the importance of timely updates to maintain robust security practices.
Affected Version(s)
Concrete CMS 9.0 <= 9.5.0
