CVE-2026-8134CRITICALCVSS 7.2

Concrete CMS Vulnerable to Relative Path Traversal

Published May 21, 2026·Updated Jun 23, 2026

Description

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code in files saved with image extensions like .png), this can result in authenticated remote code execution. Concrete CMS thanks Yonatan Drori (Tenzai) for reporting this issue.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free