9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code in files saved with image extensions like .png), this can result in authenticated remote code execution. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 9.4 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Thanks Yonatan Drori (Tenzai) for reporting.
AI Analysis
Authenticated remote code execution via path traversal and PHP file inclusion
Basic Information
ID
CVE-2026-8134
Source
ConcreteCMS
Published
May 21, 2026 at 20:13
Affected Product
Vendor
Concrete CMS
Product
Concrete CMS
Version
9.5.0
Affected Versions
Concrete CMS Concrete CMS 5.0
CWE Classification
AI Assessment
AI Score
9.4 / 10
AI Severity
Critical
Vendor
Concrete CMS
Product
Concrete CMS
Version
9.5.0 and below