Medium severity4.3NVD Advisory· Published May 22, 2026· Updated Jul 23, 2026
CVE-2026-8340
CVE-2026-8340
Description
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor's unpublished version). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 9.5.1 | 9.5.1 |
Affected products
2- Range: <=9.5.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-xjg6-5v39-v7fcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-8340ghsaADVISORY
- documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notesnvdRelease NotesWEB
News mentions
1- Concrete CMS: 25 CVEs Disclosed Together, 12 High-Severity CSRF Bugs Lead the BatchVypr Intelligence · May 22, 2026