CSRF Vulnerability in Concrete CMS Versions Below 9.5.0
CVE-2026-8417

7.5HIGH

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8417?

Versions of Concrete CMS prior to 9.5.0 are susceptible to a CSRF vulnerability that allows authenticated administrators to unknowingly trigger package upgrades. The flaw arises from a lack of CSRF token validation in the request handling for package updates. An attacker could exploit this vulnerability by tricking an administrator into visiting a malicious site, leading to unauthorized package installations or upgrades without their consent. This vulnerability poses a significant risk as it can compromise the integrity of installed packages on the affected CMS.

Affected Version(s)

Concrete CMS 5.0 <= 9.5.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.