216.73.216.226

CVE-2026-8134

· Published 21/05/2026 21:16 · Modified 21/05/2026 21:16

Labels: CVE-2026-8134 2026-05-21CVE-2026-8134CWE-23ff5b8ace-8b95-4078-9743-eac1ca5451de

Essential information

Published
21/05/2026 21:16
Modified
21/05/2026 21:16
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code in files saved with image extensions like .png), this can result in authenticated remote code execution. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 9.4 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H   Thanks Yonatan Drori (Tenzai) for reporting.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff5b8ace-8b95-4078-9743-eac1ca5451de
NVD
View on NVD

Affected products (CPE)

ProductCPE
concrete / cms cpe:2.3:a:concrete:cms:<9.5.0:*:*:*:*:*:*:*

References