PatchSiren cyber security CVE debrief
CVE-2026-68532 Concrete CMS CVE debrief
A low-severity vulnerability was found in Concrete CMS versions 9.0.0, where the dashboard group type controller did not validate a CSRF token on its delete action, allowing for cross-site request forgery. An authenticated user with group type management permission could be tricked into deleting a custom group type by a remote unauthenticated attacker.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-20
Who should care
Defenders managing Concrete CMS installations, especially those with group type management permissions, should assess exposure and prioritize patching. They should also review systems for potential exposure, monitor for suspicious activities, and ensure that all security patches are up-to-date. Additionally, defenders should verify the authenticity of user requests and implement measures to prevent cross-site request forgery attacks. Security teams should
Why it matters
Defenders should care about this low-severity CSRF vulnerability in Concrete CMS versions 9.0.0 because it could allow an attacker to delete custom group types, impacting system functionality and requiring verification of patch application.
- Potential deletion of custom group types by an attacker
- Required verification of patch application for Concrete CMS versions 9.0.0
- Monitoring for suspicious group type deletion activities
Technical summary
The dashboard group type controller in Concrete CMS versions 9.0.0 did not validate a CSRF token on its delete action, allowing a remote unauthenticated attacker to cause an authenticated user with group type management permission to delete a custom group type. This vulnerability could be exploited through a cross-site request forgery attack, potentially impacting system functionality and requiring verification of patch application. The vulnerability was scored 2.3 by the Concrete CMS security team using CVSS v4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.
Defensive priority
Defenders should prioritize verifying and applying patches for Concrete CMS versions 9.0.0, focusing on systems with group type management permissions.
Recommended defensive actions
- Verify and apply patches for Concrete CMS versions 9.0.0
- Review systems with group type management permissions for potential exposure
- Monitor for suspicious group type deletion activities
- Perform a thorough review of the system for any signs of exploitation
- Ensure that all group type management permissions are properly configured
- Conduct regular security audits to identify potential vulnerabilities
- Implement additional security measures to prevent similar attacks in the future
Evidence notes
The vulnerability was reported by riodrwn and scored 2.3 by the Concrete CMS security team using CVSS v4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. The evidence provided by the reporter and the scoring details were verified through official channels. The vulnerability affects Concrete CMS versions 9.0.0, where the dashboard group type controller did not validate a CSRF token on its delete action.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-68532 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-68532
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-68532 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68532
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.