CVE-2026-8140
Concrete CMS Concrete CMS, concrete cms
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dashboard/extend/install.php checks only the canInstallPackages() permission before fetching a remote marketplace package and writing it to the server's DIR_PACKAGES directory. Because the endpoint is a state-changing GET route with no token enforcement, an attacker who can cause an authenticated administrator to visit a crafted page can force an arbitrary marketplace package to be downloaded. In or...
- CVSS
- 7.5
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.05.22