CVE-2026-8426
Last modified
CVE-2026-8426 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID can overwrite the package PHP on disk and force its upgrade() method to execute in a single browser navigation. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID can overwrite the package PHP on disk and force its upgrade() method to execute in a single browser navigation. This results in remote code execution as the web server user. In order to be vulnerable, the victim must be passing canInstallPackages, victim site must be connected to the Concrete marketplace; and the attacker controls the package returned for a marketplace item ID already installed on the victim site. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks https://github.com/maru1009 for reporting.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 9.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-8426?
How severe is CVE-2026-8426?
How do I fix CVE-2026-8426?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84238Unauthenticated Broken Access Control in YITH Request a Quot…9.8
- CVE-2026-84239IBM Guardium Data Protection 12.2 could allow a remote authe…7.6
- CVE-2026-8424The Remove Yellow BGBOX plugin for WordPress is vulnerable t…4.3
- CVE-2026-84241IBM Guardium Data Protection 12.2 could allow a remote attac…8.1
- CVE-2026-8425The Notify Odoo plugin for WordPress is vulnerable to Cross-…4.3
- CVE-2026-84256An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22…7.7
- CVE-2026-84267A flaw was found in the SFTP backend in gvfs. When mounting …4.3
- CVE-2026-84268A flaw was found in the SFTP backend in gvfs. When mounting …8.8
- CVE-2026-84269A flaw was found in the AFP backend in gvfs. When mounting a…6.5
- CVE-2026-8427Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Requ…8.8
- CVE-2026-84270A flaw was found in the MTP backend in gvfs. When reading a …4.3
- CVE-2026-84279The Fancy Product Designer plugin for WordPress is vulnerabl…7.2
Are you affected by CVE-2026-8426?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
