CVE 9.4 CRITICAL

Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion_CVE-2026-8134

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code in files saved with image extensions like .png), this can result in authenticated remote code execution. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 9.4 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Thanks Yonatan Drori (Tenzai) for reporting.

AI Analysis

Authenticated remote code execution via path traversal and PHP file inclusion

Basic Information

ID CVE-2026-8134
Source ConcreteCMS
Published May 21, 2026 at 20:13

Affected Product

Vendor Concrete CMS
Product Concrete CMS
Version 9.5.0
Affected Versions Concrete CMS Concrete CMS 5.0

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor Concrete CMS
Product Concrete CMS
Version 9.5.0 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.