PT-2026-42536 · Unknown · Concrete Cms

·

CVE-2026-8135

·

Published

2026-05-21

·

Updated

2026-05-26

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.1
Description Remote Code Execution (RCE) is possible due to insecure deserialization in the ExpressEntryList block controller. An administrator with permissions to add blocks can bypass the fromCIF === true protection mechanism by using the REST API. Since the REST API utilizes json decode(), the string "true" is interpreted as a PHP Boolean(true), allowing the injection of a malicious serialized payload into the filterFields database column. This payload executes when an administrator views or edits the block data, potentially leading to a full server takeover.
Recommendations Update to a version newer than 9.5.0. As a temporary workaround, restrict administrator privileges to prevent unauthorized users from adding blocks to areas until the update is applied.

Exploit

Fix

RCE

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8135
GHSA-PV2V-6W2V-97X6

Affected Products

Concrete Cms