CVE-2026-7882

Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws an error when the token IS valid and proceeds with file deletion when the token is invalid or missing. This effectively disables CSRF protection for the file deletion endpoint, allowing cross-site request forgery attacks against users who have permission to edit conversation messages. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with a vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Mandani for reporting.
Configurations

Configuration 1 (hide)

cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) Concrete CMS 9.5.0 y versiones anteriores es vulnerable a la eliminación de archivos no autorizada debido a una verificación de token CSRF invertida en el controlador DeleteFile. El código arroja un error cuando el token ES válido y procede con la eliminación de archivos cuando el token es inválido o falta. Esto deshabilita efectivamente la protección CSRF para el punto final de eliminación de archivos, permitiendo ataques de falsificación de petición en sitios cruzados contra usuarios que tienen permiso para editar mensajes de conversación. El equipo de seguridad de Concrete CMS otorgó a esta vulnerabilidad una puntuación CVSS v.4.0 de 2.3 con un vector de CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Gracias a Tristan Mandani por el informe.

26 May 2026, 14:56

Type Values Removed Values Added
References () https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes - () https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes - Release Notes
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
First Time Concretecms concrete Cms
Concretecms
CPE cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*

21 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 22:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-7882

Mitre link : CVE-2026-7882

CVE.ORG link : CVE-2026-7882


JSON object : View

Products Affected

concretecms

  • concrete_cms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)