PT-2026-42535 · Unknown · Concrete Cms
Yonatan Drori
·
Published
2026-05-21
·
Updated
2026-05-26
·
CVE-2026-8134
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.1
Description
Concrete CMS fails to sanitize path traversal sequences in the
ptComposerFormLayoutSetControlCustomTemplate field during the process of saving page type composer form layouts. An authenticated administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. When combined with the file uploader's extension-only validation, which allows PHP code to be saved within files using image extensions such as .png, this can lead to authenticated remote code execution (RCE), which is the ability to execute arbitrary commands on the target server remotely.Recommendations
Update to a version newer than 9.5.0.
As a temporary workaround, restrict composer form editing rights to only highly trusted administrators.
Fix
RCE
Unrestricted File Upload
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Concrete Cms