CSRF Vulnerability in Concrete CMS Versions Below 9.5.0
CVE-2026-8417
7.5HIGH
What is CVE-2026-8417?
Versions of Concrete CMS prior to 9.5.0 are susceptible to a CSRF vulnerability that allows authenticated administrators to unknowingly trigger package upgrades. The flaw arises from a lack of CSRF token validation in the request handling for package updates. An attacker could exploit this vulnerability by tricking an administrator into visiting a malicious site, leading to unauthorized package installations or upgrades without their consent. This vulnerability poses a significant risk as it can compromise the integrity of installed packages on the affected CMS.
Affected Version(s)
Concrete CMS 5.0 <= 9.5.0
