CVE-2026-8421

Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticated administrator to visit a crafted page,  and who has placed or caused a package to be present under DIR_PACKAGES/<handle>/, can force the installation of that package without any CSRF protection. Package installation executes the package controller's install() method as the web server user, enabling remote code execution.  In order to be vulnerable, the victim must be passing canInstallPackages. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks  https://github.com/maru1009  for reporting.
Configurations

Configuration 1 (hide)

cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) Concrete CMS 9.5.0 y versiones anteriores contiene una vulnerabilidad CSRF en el método install_package() de concrete/controllers/single_page/dashboard/extend/install.php. Un atacante que puede hacer que un administrador autenticado visite una página manipulada, y que ha colocado o hecho que un paquete esté presente bajo DIR_PACKAGES/<handle>/, puede forzar la instalación de ese paquete sin ninguna protección CSRF. La instalación del paquete ejecuta el método install() del controlador del paquete como el usuario del servidor web, lo que permite la ejecución remota de código. Para ser vulnerable, la víctima debe estar pasando canInstallPackages. El equipo de seguridad de Concrete CMS otorgó a esta vulnerabilidad una puntuación CVSS v.4.0 de 7.5 con el vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Gracias a https://github.com/maru1009 por informar.

26 May 2026, 14:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
First Time Concretecms concrete Cms
Concretecms
References () https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes - () https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes - Release Notes

21 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 21:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-8421

Mitre link : CVE-2026-8421

CVE.ORG link : CVE-2026-8421


JSON object : View

Products Affected

concretecms

  • concrete_cms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)