CVE-2026-2994
PHP vulnerability analysis and mitigation

Overview

CVE-2026-2994 is a Cross-Site Request Forgery (CSRF) vulnerability in Concrete CMS affecting all versions below 9.4.8. A rogue administrator can exploit the Anti-Spam Allowlist Group Configuration via the group_id parameter to bypass security controls, because configuration changes are saved before the CSRF token is validated. The vulnerability was reported by researcher z3rco and disclosed on March 4, 2026. The Concrete CMS security team assigned a CVSS v4.0 score of 2.3 (Low), while NVD assigned a CVSS v3.1 score of 6.8 (Medium) (Feedly, ConcreteCMS Release Notes).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery). The root cause is a logic flaw in the Anti-Spam Allowlist Group Configuration handler, where the application persists changes to the group_id parameter before performing CSRF token validation — effectively rendering the CSRF protection ineffective. An attacker with administrator-level access who can trick another administrator into visiting a malicious page can forge requests that alter spam filtering group settings without proper authorization. The fix was implemented in GitHub pull request #12826, merged into the 9.4.x branch on March 3, 2026 (GitHub PR, ConcreteCMS Release Notes).

Impact

Successful exploitation allows a rogue administrator to manipulate Anti-Spam Allowlist Group Configuration settings without proper authorization, potentially altering spam filtering rules and security configurations within the Concrete CMS installation. The impact is limited to integrity — specifically low-severity modifications to security settings — with no confidentiality or availability impact. While the scope is constrained to the affected system's spam protection mechanisms, unauthorized changes to allowlist groups could result in spam bypass or weakened email filtering controls (Feedly).

Exploitability

A proof-of-concept reference exists in the form of the GitHub pull request that patches the vulnerability, but no dedicated weaponized exploit or active in-the-wild exploitation has been reported. The EPSS score is approximately 0.019% (0.000190), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already have administrator-level access and to socially engineer another administrator into triggering the forged request (Feedly, GitHub PR).

Exploitation steps

  1. Prerequisite: The attacker must be a rogue administrator or have compromised an administrator account on a Concrete CMS instance running a version below 9.4.8.
  2. Craft malicious request: Construct a forged HTTP request targeting the Anti-Spam Allowlist Group Configuration endpoint, manipulating the group_id parameter to the desired value.
  3. Deliver CSRF payload: Host a malicious web page containing a hidden form or JavaScript that automatically submits the forged request to the target Concrete CMS instance.
  4. Trigger victim interaction: Lure a logged-in Concrete CMS administrator to visit the malicious page (e.g., via phishing or a crafted link), causing their browser to submit the forged request with their session credentials.
  5. Security bypass achieved: Because the application saves the configuration change before validating the CSRF token, the group_id modification is persisted, altering the Anti-Spam Allowlist Group settings without proper authorization (Feedly, GitHub PR).

Indicators of compromise

  • Logs: Unexpected POST requests to the Anti-Spam Allowlist Group Configuration endpoint in the Concrete CMS access logs, particularly with unusual group_id values or originating from unexpected IP addresses.
  • Application State: Unexplained changes to Anti-Spam Allowlist Group settings in the Concrete CMS admin panel, especially if no administrator recalls making such changes.
  • Network: HTTP requests to the spam allowlist configuration endpoint from referrer URLs that are external or unrecognized domains, which may indicate a CSRF delivery page.

Mitigation and workarounds

Upgrade Concrete CMS to version 9.4.8 or later, which resolves this vulnerability by ensuring CSRF token validation occurs before configuration changes are saved. The patch is available via the official 9.4.8 release and was merged in GitHub pull request #12826. As an interim measure, restrict administrative access to Anti-Spam Allowlist Group Configuration settings to trusted personnel only, and implement network-level controls to limit access to sensitive administrative functions (ConcreteCMS Release Notes, GitHub PR).

Community reactions

The vulnerability was acknowledged by the Concrete CMS security team, who assigned their own CVSS v4.0 score of 2.3 (Low), reflecting a more conservative severity assessment than the NVD's CVSS v3.1 score of 6.8 (Medium). The disclosure credited researcher z3rco for responsible reporting. No significant broader media coverage or notable researcher commentary beyond the official disclosure has been identified (Feedly).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-52777CRITICAL9.4
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52775HIGH8.8
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52774MEDIUM6.1
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52773MEDIUM6.1
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52772MEDIUM5.5
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management