Junglewise Threat Intelligence

CVE-2026-8135: Concrete CMS insecure deserialization in ExpressEntryList block

CVE-2026-8135 · Severity: high · CVSS 4 · Published 2026-05-21

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a popular content management system, is vulnerable to a security flaw that could allow a malicious administrator to take full control of the web server. By exploiting a weakness in how the system handles data through its programming interface (API), an attacker can run unauthorized commands on the server. This could lead to the theft of sensitive customer data, complete service outages, or the use of the server for further attacks.

Technical details

Concrete CMS 9.5.0 and below contains an insecure deserialization vulnerability within the ExpressEntryList block controller. The root cause is a type-juggling bypass of the '_fromCIF === true' protection mechanism; while standard POST requests treat the input as a string, the REST API uses json_decode(), which evaluates the input as a strict PHP Boolean(true). An authenticated attacker with administrative privileges to add blocks can leverage this bypass to inject a malicious serialized payload into the 'filterFields' database column. Remote code execution is triggered when another administrator views or edits the affected block. The issue is resolved in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS <= 9.5.0

Timeline

  • 2026-05-21: advisory: Initial disclosure by Concrete CMS and GitHub Advisory Database
  • 2026-05-21: patched: Version 9.5.1 released to address the vulnerability

References

Related threats