Sploitus

CVE-2026-8350

No indexed exploits for CVE-2026-8350 yet

Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add any user email to any group and can remove legitimate admins. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Vincent55 for reporting.

Affected products
Concrete Cms
Concretecms Concrete Cms
≤ 9.5.0
CVSS 3.1
8.8 HIGH
EPSS
0.3% (22th percentile)
Weakness
CWE-863
NVD status
Analyzed
Published
2026-05-21
Attack patterns
CAPEC-1
CVE-2026-8350 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-8350 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-8350 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.