CRITICAL🇵🇱 Wersja polska

CVE-2026-8134

CVSS 9.4v4.0pub. 2026-05-21upd. 2026-05-26

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code in files saved with image extensions like .png), this can result in authenticated remote code execution. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 9.4 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H   Thanks Yonatan Drori (Tenzai) for reporting.

🤖 AI Analysis
How it works

An authenticated administrator with permissions to edit composer forms can inject path traversal sequences (e.g., '../') into the ptComposerFormLayoutSetControlCustomTemplate field while saving form layouts on the page. This mechanism allows inclusion of any readable file on the server. Since the file uploader validates only the extension (not the actual content), an attacker can previously upload a file containing PHP code saved with a graphics extension (e.g., .png), and then force its inclusion through the vulnerable field – resulting in execution of malicious PHP code.

Impact

An attacker can read arbitrary files accessible to the web server process and execute arbitrary code on the server (RCE), which may lead to complete takeover of the system and the environment hosting the application.

Mitigation & patch

Concrete CMS should be updated to version 9.5.1 or newer according to the vendor information available at: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes

Who is affected

Concrete CMS in version 9.5.0 and lower

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Concretecms Concrete Cms

    APP
    Concretecms
    ≤ 9.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2023-48648CRITICAL9.8PL ✓same product

Concrete CMS — nieautoryzowany dostęp przez nieprawidłowe uprawnienia katalogów

CVE-2022-30117CRITICAL9.1PL ✓same product

Concrete CMS — path traversal umożliwiający usunięcie dowolnych plików

CVE-2022-21829CRITICAL9.8PL ✓same product

Concrete CMS – pobieranie i wykonanie kodu z plików ZIP przez HTTP (RCE)

CVE-2021-22958CRITICAL9.8PL ✓same product

SSRF w Concrete CMS — ominięcie blokady localhost przez zapis dziesiętny IP

CVE-2021-40098CRITICAL9.8PL ✓same product

Path Traversal prowadzący do RCE w Concrete CMS przez external form