PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-68532 Concrete CMS CVE debrief

A low-severity vulnerability was found in Concrete CMS versions 9.0.0, where the dashboard group type controller did not validate a CSRF token on its delete action, allowing for cross-site request forgery. An authenticated user with group type management permission could be tricked into deleting a custom group type by a remote unauthenticated attacker.

Vendor
Concrete CMS
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-20
Advisory published
2026-09-15
Advisory updated
2026-09-20

Who should care

Defenders managing Concrete CMS installations, especially those with group type management permissions, should assess exposure and prioritize patching. They should also review systems for potential exposure, monitor for suspicious activities, and ensure that all security patches are up-to-date. Additionally, defenders should verify the authenticity of user requests and implement measures to prevent cross-site request forgery attacks. Security teams should

Why it matters

Defenders should care about this low-severity CSRF vulnerability in Concrete CMS versions 9.0.0 because it could allow an attacker to delete custom group types, impacting system functionality and requiring verification of patch application.

  • Potential deletion of custom group types by an attacker
  • Required verification of patch application for Concrete CMS versions 9.0.0
  • Monitoring for suspicious group type deletion activities

Technical summary

The dashboard group type controller in Concrete CMS versions 9.0.0 did not validate a CSRF token on its delete action, allowing a remote unauthenticated attacker to cause an authenticated user with group type management permission to delete a custom group type. This vulnerability could be exploited through a cross-site request forgery attack, potentially impacting system functionality and requiring verification of patch application. The vulnerability was scored 2.3 by the Concrete CMS security team using CVSS v4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.

Defensive priority

Defenders should prioritize verifying and applying patches for Concrete CMS versions 9.0.0, focusing on systems with group type management permissions.

Recommended defensive actions

  • Verify and apply patches for Concrete CMS versions 9.0.0
  • Review systems with group type management permissions for potential exposure
  • Monitor for suspicious group type deletion activities
  • Perform a thorough review of the system for any signs of exploitation
  • Ensure that all group type management permissions are properly configured
  • Conduct regular security audits to identify potential vulnerabilities
  • Implement additional security measures to prevent similar attacks in the future

Evidence notes

The vulnerability was reported by riodrwn and scored 2.3 by the Concrete CMS security team using CVSS v4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. The evidence provided by the reporter and the scoring details were verified through official channels. The vulnerability affects Concrete CMS versions 9.0.0, where the dashboard group type controller did not validate a CSRF token on its delete action.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-68532 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-68532

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-68532 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68532

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.