Executive brief
Concrete CMS, a content management system used for building and managing websites, is vulnerable to a security flaw in its Permission, Cache, and Search components. If an attacker can place malicious data into the website's database, they can force the system to execute unintended code. This could lead to a complete takeover of the website, unauthorized access to sensitive data, or service disruption.
Technical details
Concrete CMS versions prior to 9.5.2 are vulnerable to PHP Object Injection (CWE-502) due to the insecure use of the PHP unserialize() function without restricting allowed classes. The vulnerability exists within the Permission, Cache, and Search components. An attacker with the ability to inject a malicious serialized payload into the database (requiring high privileges or a separate vulnerability) can trigger arbitrary PHP object instantiation when the system subsequently processes that data. This can lead to remote code execution depending on the available gadget chains. The issue is mitigated in version 9.5.2 by implementing the 'allowed_classes' option in unserialize() calls.
Affected products
- Concrete CMS Concrete CMS < 9.5.2
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory
- 2026-08-12: patched: Advisory updated to reflect patch in 9.5.2