PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8412 Concrete CMS CVE debrief

CVE-2026-8412 is a low-severity CSRF issue in Concrete CMS 9 before 9.5.0, affecting the bulk cache controller path. The CVE was published on 2026-05-21 and scored CVSS v4.0 2.3, indicating a network-reachable issue that requires user interaction and is expected to cause only limited integrity impact. The safest response is to upgrade to the fixed Concrete CMS version and verify the bulk cache workflow now enforces anti-CSRF protections.

Vendor
Concrete CMS
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-07-23
Advisory published
2026-05-21
Advisory updated
2026-07-23

Who should care

Concrete CMS 9 site owners, administrators, and maintainers running versions before 9.5.0, especially teams that use or expose bulk cache management workflows to authenticated users.

Technical summary

NVD describes CVE-2026-8412 as a CSRF weakness at concrete/controllers/dialog/page/bulk/cache in Concrete CMS 9 before 9.5.0. A victim with an active authenticated session could be induced to send a forged request that triggers an unintended cache-related state change. The NVD metadata lists CWE-352 and CWE-1275, and the published CVSS v4.0 vector reflects required user interaction with limited integrity impact.

Defensive priority

Low to moderate. This is not an emergency based on the published CVSS 2.3 score, but it should be corrected on a normal maintenance timeline because CSRF in an admin workflow can still change state without user intent.

Recommended defensive actions

  • Upgrade Concrete CMS 9.x to 9.5.0 or later.
  • Confirm the affected bulk cache controller path now requires and validates anti-CSRF protections.
  • Verify administrative workflows are restricted to trusted users and that sessions are protected by standard hardening controls.
  • Use the Concrete CMS release notes referenced by NVD to confirm the fixed version and any follow-up guidance.

Evidence notes

The CVE record and NVD metadata published on 2026-05-21 identify a CSRF issue in Concrete CMS 9 before 9.5.0, with CVSS v4.0 2.3 and the vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. The NVD reference list links to Concrete CMS version-history release notes as the vendor-side source.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8412 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8412

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8412 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8412

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.