Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST… (CVE-2026-81907)
Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforce a failed CSRF token check, allowing the destructive operation to proceed when the token is missing or invalid. A remote unauthenticated attacker can force an authenticated administrator who visits an attacker-controlled page to permanently delete all entries belonging to an attacker-selected Express entity on a web application to which the administrator is currently authenticated. Because the default Contact Express object ships with a fixed entity UUID, the target identifier can be obtained without dashboard access. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Pratik Zanjurne for reporting.
AI Analysis
Technical Summary
Concrete CMS 9.5.2 and earlier versions are vulnerable to CSRF in the Express "Clear Entries" POST endpoint (/index.php/dashboard/system/express/entities/delete_entries). The controller records failed CSRF token checks but does not prevent the operation from proceeding when the token is missing or invalid. This allows a remote unauthenticated attacker to cause an authenticated administrator to delete all entries of an attacker-selected Express entity. The fixed UUID of the default Contact Express object allows the attacker to identify the target entity without dashboard access. The vulnerability has a CVSS v4.0 score of 6.1, indicating a medium severity impact.
Potential Impact
An attacker can remotely induce an authenticated administrator to perform destructive actions, specifically deleting all entries of a selected Express entity. This results in permanent data loss for that entity. The attack requires the administrator to visit a malicious page but does not require the attacker to be authenticated. The vulnerability affects data integrity and availability for the affected Express entities.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should avoid visiting untrusted or attacker-controlled web pages while authenticated to the Concrete CMS dashboard. Monitor official Concrete CMS channels for updates and patches addressing this CSRF vulnerability.
Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST… (CVE-2026-81907)
Description
Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforce a failed CSRF token check, allowing the destructive operation to proceed when the token is missing or invalid. A remote unauthenticated attacker can force an authenticated administrator who visits an attacker-controlled page to permanently delete all entries belonging to an attacker-selected Express entity on a web application to which the administrator is currently authenticated. Because the default Contact Express object ships with a fixed entity UUID, the target identifier can be obtained without dashboard access. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Pratik Zanjurne for reporting.
CVSS v4.0
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Concrete CMS 9.5.2 and earlier versions are vulnerable to CSRF in the Express "Clear Entries" POST endpoint (/index.php/dashboard/system/express/entities/delete_entries). The controller records failed CSRF token checks but does not prevent the operation from proceeding when the token is missing or invalid. This allows a remote unauthenticated attacker to cause an authenticated administrator to delete all entries of an attacker-selected Express entity. The fixed UUID of the default Contact Express object allows the attacker to identify the target entity without dashboard access. The vulnerability has a CVSS v4.0 score of 6.1, indicating a medium severity impact.
Potential Impact
An attacker can remotely induce an authenticated administrator to perform destructive actions, specifically deleting all entries of a selected Express entity. This results in permanent data loss for that entity. The attack requires the administrator to visit a malicious page but does not require the attacker to be authenticated. The vulnerability affects data integrity and availability for the affected Express entities.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should avoid visiting untrusted or attacker-controlled web pages while authenticated to the Concrete CMS dashboard. Monitor official Concrete CMS channels for updates and patches addressing this CSRF vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3hj2-5gr2-79cm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-81907"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6aa49ff555bf5e2cf5a8659b
Added to database: 09/12/2026, 00:42:29 UTC
Last enriched: 09/12/2026, 00:46:05 UTC
Last updated: 09/12/2026, 00:47:06 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.