PT-2026-42546 · Unknown · Concrete Cms

·

CVE-2026-8350

·

Published

2026-05-21

·

Updated

2026-05-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9.5.0 and earlier
Description Missing authorization in the 'bulk user assignment.php' endpoint allows an authenticated user with access to the bulk user assignment dashboard page to perform privilege escalation to the Administrative Group. This allows the user to add any email address to any group or remove legitimate administrators.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8350
GHSA-G7XP-JF3X-WCX4

Affected Products

Concrete Cms