CVE-2026-3452Disclosure(concretecms / concrete_cms)

LOWCVSS 7.2 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can store attacker-controlled serialized data in block configuration fields that are later passed to unserialize() without class restrictions or integrity checks. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.9 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. Thanks YJK ( @YJK0805 https://hackerone.com/yjk0805 ) of ZUSO ART https://zuso.ai/  for reporting.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • concrete_cms

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Products
concrete_cms

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-04: 5Technical Details · 2026-03-04: 503-04
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Full discourse5 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3452 📊 Severity: 8.9 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3452 #CVE-2026-3452 #CVE #High #CyberSecurity #InfoSec https://t.co/RgwD1ByI7M

    Post summary

    The tweet is a brief alert about CVE‑2026‑3452, noting its high severity but providing no exploit details, patches, or evidence of active use.

    0000037
    64 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3452 - Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block. Intel Report: https://ift.tt/SlWRYO8

    Post summary

    The alert announces CVE-2026-3452, a stored deserialization flaw in Concrete CMS versions below 9.4.8 that can lead to remote code execution in the Express Entry List block, with no PoC, exploit, or patch details provided.

    0000045
    344 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3452 Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An a… https://www.cve.org/CVERecord?id=CVE-2026-3452 ----- Traducción: CVE-2026-3452 Con… http://infoflow.cloud`

    Post summary

    Concrete CMS versions below 9.4.8 are vulnerable to remote code execution through stored PHP object injection in the Express Entry List block, as detailed in CVE-2026-3452.

    0000028
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3452 Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An a… https://www.cve.org/CVERecord?id=CVE-2026-3452

    Post summary

    Concrete CMS versions below 9.4.8 are vulnerable to remote code execution through stored PHP object injection in the Express Entry List block’s columns parameter.

    00000227
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3452 Remote Code Execution in Concrete CMS via Stored PHP Object Inject... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3452 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new CVE (CVE-2026-3452) has been disclosed, describing a remote code execution vulnerability in Concrete CMS via stored PHP object injection.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconcretecmsconcrete_cms---

Explore more