Junglewise Threat Intelligence

CVE-2026-8415: Concrete CMS CSRF in Express association reordering

CVE-2026-8415 · Severity: medium · CVSS 4 · Published 2026-05-21

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a popular content management system, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. Specifically, an attacker could force a logged-in user to reorder data associations within the system without their consent. While this does not directly expose sensitive data, it can disrupt site organization and data integrity if a user is successfully deceived into clicking a malicious link.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Concrete CMS versions 9.0.0RC1 through 9.5.0. The flaw is located in the 'concrete/controllers/dialog/express/association/reorder' controller, which fails to properly validate CSRF tokens before processing reordering requests. An attacker can exploit this by inducing a logged-in administrator to visit a malicious webpage or click a crafted link, leading to unauthorized changes in Express data associations. The vulnerability is mitigated by the requirement for user interaction and the specific nature of the affected component. The issue is addressed in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS 9.0.0RC1 to 9.5.0

Timeline

  • 2026-05-21: disclosed: NVD publication date
  • 2026-05-22: advisory: GitHub Advisory published
  • 2026-06-24: patched: Advisory updated with patch information

References

Related threats