Executive brief
Concrete CMS is a content management system used to build and manage websites. A security flaw in the log management component allows an attacker to trick an administrator into unintentionally deleting system logs. This could be used by an attacker to hide their tracks after performing other malicious activities on the site.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Concrete CMS versions 9.0.0RC1 through 9.5.0 within the 'concrete/controllers/dialog/logs/delete' component. The application fails to properly validate CSRF tokens or implement sufficient SameSite cookie attributes for requests to the log deletion endpoint. An unauthenticated attacker can exploit this by inducing a logged-in administrator to visit a malicious webpage, leading to the unauthorized deletion of system logs. This vulnerability is tracked as CVE-2026-8409 and has been addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS 9.0.0RC1 through 9.5.0
Timeline
- 2026-05-21: disclosed: NVD Published Date
- 2026-05-22: advisory: GitHub Advisory published
- 2026-06-24: patched: Advisory updated with patch information for version 9.5.1