Description
Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group type. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-15
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery leading to unauthorized deletion of group types
Action: Assess Impact
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 allow a remote unauthenticated attacker to delete a custom group type because the dashboard delete action does not validate a CSRF token. The attacker can trigger the deletion via a crafted link or form presented to an authenticated user with group‑type‑management permission. The exploit does not provide direct access to other data, but it compromises the site’s configuration and organization by removing a group type that may be used for access control or content association.

Affected Systems

Concrete CMS instances running any version from 9.0.0 up to and including 9.5.2 are affected. The vulnerability exists in the CMS platform’s dashboard group‑type controller and applies to any installation where group‑type‑management roles are granted.

Risk and Exploitability

The CVSS v4.0 score of 2.3 indicates a low severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation. The attack requires that the victim be logged into the CMS with appropriate permissions and that the attacker can reach the dashboard endpoint, so the conditions are limited. This vulnerability is not listed in the CISA KEV catalog, implying it has not been widely exploited in the wild. The likely attack vector is a remote unprivileged actor sending a CSRF request to an authenticated user; this vector is inferred from the description and the absence of explicit mention of authentication requirements.

Generated by OpenCVE AI on September 20, 2026 at 13:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to a version newer than 9.5.2 where CSRF validation is enforced for the delete action.
  • Restrict or remove group‑type‑management permissions to only trusted users who truly need that capability.
  • Enable logging and audit of group‑type deletion events to detect and investigate unauthorized changes.

Generated by OpenCVE AI on September 20, 2026 at 13:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group type. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashboard Action
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-20T00:45:42.976Z

Reserved: 2026-07-30T18:04:50.763Z

Link: CVE-2026-68532

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:06.572Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:37.033

Modified: 2026-09-20T01:16:29.437

Link: CVE-2026-68532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:45:07Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)