CVE-2026-7888
Last modified
CVE-2026-7888 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.2; the Workflow component sinks were addressed in 9.5.3. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for independently reporting the original components, and sh4d0byss for reporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/ VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7888?
How severe is CVE-2026-7888?
How do I fix CVE-2026-7888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78847An issue in gray-matter All versions (verified on 4.0.3) all…9.8
- CVE-2026-78849Cross Site Scripting vulnerability in Netgate pfSense Plus s…5.4
- CVE-2026-7886Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMes…4.3
- CVE-2026-78863A vulnerability was found in liketrek TREK up to 3.0.22. Imp…6.3
- CVE-2026-78864A vulnerability was determined in liketrek TREK up to 3.0.22…6.3
- CVE-2026-7887For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Co…6.4
- CVE-2026-78885A vulnerability was identified in liketrek TREK up to 3.0.22…5.6
- CVE-2026-78886A security flaw has been discovered in liketrek TREK up to 3…3.7
- CVE-2026-78887A weakness has been identified in liketrek TREK up to 3.0.22…3.7
- CVE-2026-78891Buffer overflow in WebRTC in Google Chrome prior to 152.0.79…8.8
- CVE-2026-78892Incorrect authorization in Chromoting in Google Chrome on on…7.1
- CVE-2026-78893Information leak in QUIC in Google Chrome prior to 152.0.797…6.5
Are you affected by CVE-2026-7888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
