CVE-2026-2994: Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allowlist Group
Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via groupid parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token.
The Concrete CMS security team thanks z3rco for reporting
Other sources
Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via groupid parameter which can leads to a security bypass since changes are saved prior to checking the CSRF token. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks z3rco for reporting
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2994?
CVE-2026-2994 has a high severity due to its potential to allow a Rogue Administrator to exploit CSRF vulnerabilities.
How do I fix CVE-2026-2994?
To fix CVE-2026-2994, upgrade Concrete CMS to a version higher than 9.4.8.
What type of vulnerability is CVE-2026-2994?
CVE-2026-2994 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2026-2994?
CVE-2026-2994 affects all users of Concrete CMS versions below 9.4.8.
What can an attacker do with CVE-2026-2994?
An attacker can potentially bypass security measures and alter settings in Concrete CMS by exploiting the CSRF vulnerability.