Cross Site Request Forgery in Concrete CMS Affects Multiple Versions
CVE-2026-8414

2.3LOW

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8414?

Concrete CMS versions prior to 9.5.0 are exposed to a Cross Site Request Forgery (CSRF) vulnerability located in the event duplication controller. This flaw allows an attacker to perform unauthorized actions on behalf of an authenticated user, potentially leading to significant security breaches. The Concrete CMS security team has confirmed the existence of this issue, which underscores the importance of upgrading to the latest version to mitigate associated risks.

Affected Version(s)

Concrete CMS 9.0 <= 9.5.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yonatan Drori (Tenzai)
.