PT-2026-48390 · Unknown · Concrete Cms

·

CVE-2026-10721

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.2
Description PHP Object Injection occurs due to insecure deserialization within the Permission, Cache, and Search components. These components use the unserialize() function on stored data without restricting allowed classes. An unauthenticated attacker can trigger arbitrary PHP object instantiation if a malicious serialized payload is placed in the database, which may lead to remote code execution. This process requires the attacker to have high privileges to write the malicious serialized data to the relevant store.
Recommendations Upgrade to version 9.5.2 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10721
GHSA-G82F-9PW7-773W

Affected Products

Concrete Cms