Sploitus

CVE-2026-8421

No indexed exploits for CVE-2026-8421 yet

Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticated administrator to visit a crafted page,  and who has placed or caused a package to be present under DIR_PACKAGES/<handle>/, can force the installation of that package without any CSRF protection. Package installation executes the package controller's install() method as the web server user, enabling remote code execution.  In order to be vulnerable, the victim must be passing canInstallPackages. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks  https://github.com/maru1009  for reporting.

Affected products
Concrete Cms
Concretecms Concrete Cms
< 9.5.1
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.2% (7th percentile)
Weakness
CWE-352
NVD status
Analyzed
Published
2026-05-21
Attack patterns
CAPEC-193
Entry point
canInstallPackages path
Path
concrete/controllers/single_page/dashboard/extend/install.php
CVE-2026-8421 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-8421 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-8421 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.