Junglewise Threat Intelligence

CVE-2026-8411: Concrete CMS CSRF in bulk page deletion controller

CVE-2026-8411 · Severity: medium · CVSS 4 · Published 2026-05-21

Technologies: concrete5/concrete5 (Packagist), Concrete CMS. Vendors: Packagist, Concrete CMS.

Executive brief

Concrete CMS is a content management system used to build and manage websites. A security flaw in the bulk page deletion feature allows an attacker to trick an administrator into unintentionally deleting website pages. This occurs if the administrator visits a malicious link while logged into the CMS, potentially leading to unauthorized data loss or site disruption.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Concrete CMS within the 'concrete/controllers/dialog/page/bulk/delete' component. The application fails to properly validate CSRF tokens or implement sufficient SameSite cookie attributes for requests targeting the bulk delete functionality. An attacker can exploit this by crafting a malicious webpage or link that, when accessed by an authenticated administrator, triggers a background request to delete multiple pages. This vulnerability is mitigated by the requirement for user interaction (the victim must click a link) and specific timing/state requirements. The issue is addressed in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS 9.0.0RC1 through 9.5.0

Timeline

  • 2026-05-21: disclosed: NVD publication date
  • 2026-05-22: advisory: GitHub Advisory published
  • 2026-06-24: patched: Advisory updated with patch information for version 9.5.1

References

Related threats