PatchSiren cyber security CVE debrief
CVE-2026-8412 Concrete CMS CVE debrief
CVE-2026-8412 is a low-severity CSRF issue in Concrete CMS 9 before 9.5.0, affecting the bulk cache controller path. The CVE was published on 2026-05-21 and scored CVSS v4.0 2.3, indicating a network-reachable issue that requires user interaction and is expected to cause only limited integrity impact. The safest response is to upgrade to the fixed Concrete CMS version and verify the bulk cache workflow now enforces anti-CSRF protections.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-07-23
Who should care
Concrete CMS 9 site owners, administrators, and maintainers running versions before 9.5.0, especially teams that use or expose bulk cache management workflows to authenticated users.
Technical summary
NVD describes CVE-2026-8412 as a CSRF weakness at concrete/controllers/dialog/page/bulk/cache in Concrete CMS 9 before 9.5.0. A victim with an active authenticated session could be induced to send a forged request that triggers an unintended cache-related state change. The NVD metadata lists CWE-352 and CWE-1275, and the published CVSS v4.0 vector reflects required user interaction with limited integrity impact.
Defensive priority
Low to moderate. This is not an emergency based on the published CVSS 2.3 score, but it should be corrected on a normal maintenance timeline because CSRF in an admin workflow can still change state without user intent.
Recommended defensive actions
- Upgrade Concrete CMS 9.x to 9.5.0 or later.
- Confirm the affected bulk cache controller path now requires and validates anti-CSRF protections.
- Verify administrative workflows are restricted to trusted users and that sessions are protected by standard hardening controls.
- Use the Concrete CMS release notes referenced by NVD to confirm the fixed version and any follow-up guidance.
Evidence notes
The CVE record and NVD metadata published on 2026-05-21 identify a CSRF issue in Concrete CMS 9 before 9.5.0, with CVSS v4.0 2.3 and the vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. The NVD reference list links to Concrete CMS version-history release notes as the vendor-side source.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8412 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8412
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8412 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8412
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.