CVE-2026-7888 (GCVE-0-2026-7888)
Vulnerability from cvelistv5
Published
2026-06-03 18:10
Modified
2026-09-11 19:04
CWE
  • CWE-502 - Deserialization of untrusted data
Summary
Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for independently reporting the original components, and sh4d0byss for reporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/ VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
Impacted products
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-7888",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-03T19:07:44.886735Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-03T19:07:56.723Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://github.com/concretecms/concretecms",
          "defaultStatus": "unaffected",
          "product": "Concrete CMS",
          "repo": "https://github.com/concretecms/concretecms",
          "vendor": "Concrete CMS",
          "versions": [
            {
              "lessThanOrEqual": "9.5.2",
              "status": "affected",
              "version": "5.0",
              "versionType": "git"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "XananasX7"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "Sanjorn Keeratirungsan (dizconnect)"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "sh4d0byss"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()\u003cbr\u003ecalls in the Workflow, Form block, and File/Set components that lack the\u003cbr\u003eallowed_classes restriction. The Form block and File/Set sinks were addressed in\u003cbr\u003e9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated\u003cbr\u003eattacker may trigger arbitrary PHP object instantiation if a malicious serialized\u003cbr\u003epayload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan\u003cbr\u003e(dizconnect) for independently reporting the original components, and sh4d0byss for\u003cbr\u003ereporting the Workflow component wasn\u0027t fixed in 9.5.2. The Concrete CMS security team gave this\u003cbr\u003evulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/\u003cbr\u003eVC:H/VI:H/VA:H/SC:N/SI:N/SA:N."
            }
          ],
          "value": "Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()\ncalls in the Workflow, Form block, and File/Set components that lack the\nallowed_classes restriction. The Form block and File/Set sinks were addressed in\n9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated\nattacker may trigger arbitrary PHP object instantiation if a malicious serialized\npayload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan\n(dizconnect) for independently reporting the original components, and sh4d0byss for\nreporting the Workflow component wasn\u0027t fixed in 9.5.2. The Concrete CMS security team gave this\nvulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/\nVC:H/VI:H/VA:H/SC:N/SI:N/SA:N."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-586",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-586 Object Injection"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-502",
              "description": "CWE-502 Deserialization of untrusted data",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-11T19:04:23.786Z",
        "orgId": "ff5b8ace-8b95-4078-9743-eac1ca5451de",
        "shortName": "ConcreteCMS"
      },
      "references": [
        {
          "tags": [
            "release-notes"
          ],
          "url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/952-release-notes"
        }
      ],
      "source": {
        "advisory": "https://hackerone.com/reports/3756743",
        "defect": [
          "HackerOne"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.",
      "x_generator": {
        "engine": "Vulnogram 1.0.2"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ff5b8ace-8b95-4078-9743-eac1ca5451de",
    "assignerShortName": "ConcreteCMS",
    "cveId": "CVE-2026-7888",
    "datePublished": "2026-06-03T18:10:10.917Z",
    "dateReserved": "2026-05-05T20:23:08.863Z",
    "dateUpdated": "2026-09-11T19:04:23.786Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-7888\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-06-03T19:07:44.886735Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-06-03T19:07:52.022Z\"}}], \"cna\": {\"title\": \"Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.\", \"source\": {\"defect\": [\"HackerOne\"], \"advisory\": \"https://hackerone.com/reports/3756743\", \"discovery\": \"EXTERNAL\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"remediation developer\", \"value\": \"XananasX7\"}, {\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Sanjorn Keeratirungsan (dizconnect)\"}, {\"lang\": \"en\", \"type\": \"finder\", \"value\": \"sh4d0byss\"}], \"impacts\": [{\"capecId\": \"CAPEC-586\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-586 Object Injection\"}]}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV4_0\": {\"Safety\": \"NOT_DEFINED\", \"version\": \"4.0\", \"Recovery\": \"NOT_DEFINED\", \"baseScore\": 8.4, \"Automatable\": \"NOT_DEFINED\", \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"valueDensity\": \"NOT_DEFINED\", \"vectorString\": \"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\", \"exploitMaturity\": \"NOT_DEFINED\", \"providerUrgency\": \"NOT_DEFINED\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"attackRequirements\": \"NONE\", \"privilegesRequired\": \"HIGH\", \"subIntegrityImpact\": \"NONE\", \"vulnIntegrityImpact\": \"HIGH\", \"subAvailabilityImpact\": \"NONE\", \"vulnAvailabilityImpact\": \"HIGH\", \"subConfidentialityImpact\": \"NONE\", \"vulnConfidentialityImpact\": \"HIGH\", \"vulnerabilityResponseEffort\": \"NOT_DEFINED\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"repo\": \"https://github.com/concretecms/concretecms\", \"vendor\": \"Concrete CMS\", \"product\": \"Concrete CMS\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.0\", \"versionType\": \"git\", \"lessThanOrEqual\": \"9.5.2\"}], \"collectionURL\": \"https://github.com/concretecms/concretecms\", \"defaultStatus\": \"unaffected\"}], \"references\": [{\"url\": \"https://documentation.concretecms.org/9-x/developers/introduction/version-history/952-release-notes\", \"tags\": [\"release-notes\"]}], \"x_generator\": {\"engine\": \"Vulnogram 1.0.2\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()\\ncalls in the Workflow, Form block, and File/Set components that lack the\\nallowed_classes restriction. The Form block and File/Set sinks were addressed in\\n9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated\\nattacker may trigger arbitrary PHP object instantiation if a malicious serialized\\npayload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan\\n(dizconnect) for independently reporting the original components, and sh4d0byss for\\nreporting the Workflow component wasn\u0027t fixed in 9.5.2. The Concrete CMS security team gave this\\nvulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/\\nVC:H/VI:H/VA:H/SC:N/SI:N/SA:N.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()\u003cbr\u003ecalls in the Workflow, Form block, and File/Set components that lack the\u003cbr\u003eallowed_classes restriction. The Form block and File/Set sinks were addressed in\u003cbr\u003e9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated\u003cbr\u003eattacker may trigger arbitrary PHP object instantiation if a malicious serialized\u003cbr\u003epayload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan\u003cbr\u003e(dizconnect) for independently reporting the original components, and sh4d0byss for\u003cbr\u003ereporting the Workflow component wasn\u0027t fixed in 9.5.2. The Concrete CMS security team gave this\u003cbr\u003evulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/\u003cbr\u003eVC:H/VI:H/VA:H/SC:N/SI:N/SA:N.\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-502\", \"description\": \"CWE-502 Deserialization of untrusted data\"}]}], \"providerMetadata\": {\"orgId\": \"ff5b8ace-8b95-4078-9743-eac1ca5451de\", \"shortName\": \"ConcreteCMS\", \"dateUpdated\": \"2026-09-11T19:04:23.786Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-7888\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-09-11T19:04:23.786Z\", \"dateReserved\": \"2026-05-05T20:23:08.863Z\", \"assignerOrgId\": \"ff5b8ace-8b95-4078-9743-eac1ca5451de\", \"datePublished\": \"2026-06-03T18:10:10.917Z\", \"assignerShortName\": \"ConcreteCMS\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…