Junglewise Threat Intelligence

CVE-2026-10721: Concrete CMS PHP object injection in Permission Cache and Search components

CVE-2026-10721 · Severity: high · CVSS 4 · Published 2026-06-10

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a content management system used for building and managing websites, is vulnerable to a security flaw in its Permission, Cache, and Search components. If an attacker can place malicious data into the website's database, they can force the system to execute unintended code. This could lead to a complete takeover of the website, unauthorized access to sensitive data, or service disruption.

Technical details

Concrete CMS versions prior to 9.5.2 are vulnerable to PHP Object Injection (CWE-502) due to the insecure use of the PHP unserialize() function without restricting allowed classes. The vulnerability exists within the Permission, Cache, and Search components. An attacker with the ability to inject a malicious serialized payload into the database (requiring high privileges or a separate vulnerability) can trigger arbitrary PHP object instantiation when the system subsequently processes that data. This can lead to remote code execution depending on the available gadget chains. The issue is mitigated in version 9.5.2 by implementing the 'allowed_classes' option in unserialize() calls.

Affected products

  • Concrete CMS Concrete CMS < 9.5.2

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory
  • 2026-08-12: patched: Advisory updated to reflect patch in 9.5.2

References

Related threats