CVE-2026-68532
Received Received - Intake

Cross-Site Request Forgery in Concrete CMS

Vulnerability report for CVE-2026-68532, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-20

Assigner: ConcreteCMS

Description

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group type.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-20
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concrete_cms concrete_cms 9.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 to a specific point had a vulnerability where the dashboard group type controller did not validate a CSRF token during its delete action. This allowed a remote unauthenticated attacker to trick an authenticated user with group type management permissions into deleting a custom group type through cross-site request forgery.

Detection Guidance

This vulnerability involves a missing CSRF token validation in Concrete CMS 9.0.0 for dashboard group type deletion. To detect it, inspect Concrete CMS logs for unauthorized group type deletions or check if the delete action in group type management does not require a CSRF token. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to cause unintended deletion of group types in Concrete CMS. This could disrupt user management, remove necessary permissions, or cause data loss if group types are critical to system operations.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards. It involves a CSRF flaw allowing unauthorized deletion of group types by authenticated users with specific permissions, which is a low-severity issue (CVSS 2.3). No data exposure or integrity loss occurs that would typically trigger regulatory concerns.

Mitigation Strategies

Update Concrete CMS to the latest version beyond 9.0.0 to ensure the CSRF token validation is properly implemented.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart