
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2994 is a Cross-Site Request Forgery (CSRF) vulnerability in Concrete CMS affecting all versions below 9.4.8. A rogue administrator can exploit the Anti-Spam Allowlist Group Configuration via the group_id parameter to bypass security controls, because configuration changes are saved before the CSRF token is validated. The vulnerability was reported by researcher z3rco and disclosed on March 4, 2026. The Concrete CMS security team assigned a CVSS v4.0 score of 2.3 (Low), while NVD assigned a CVSS v3.1 score of 6.8 (Medium) (Feedly, ConcreteCMS Release Notes).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery). The root cause is a logic flaw in the Anti-Spam Allowlist Group Configuration handler, where the application persists changes to the group_id parameter before performing CSRF token validation — effectively rendering the CSRF protection ineffective. An attacker with administrator-level access who can trick another administrator into visiting a malicious page can forge requests that alter spam filtering group settings without proper authorization. The fix was implemented in GitHub pull request #12826, merged into the 9.4.x branch on March 3, 2026 (GitHub PR, ConcreteCMS Release Notes).
Successful exploitation allows a rogue administrator to manipulate Anti-Spam Allowlist Group Configuration settings without proper authorization, potentially altering spam filtering rules and security configurations within the Concrete CMS installation. The impact is limited to integrity — specifically low-severity modifications to security settings — with no confidentiality or availability impact. While the scope is constrained to the affected system's spam protection mechanisms, unauthorized changes to allowlist groups could result in spam bypass or weakened email filtering controls (Feedly).
A proof-of-concept reference exists in the form of the GitHub pull request that patches the vulnerability, but no dedicated weaponized exploit or active in-the-wild exploitation has been reported. The EPSS score is approximately 0.019% (0.000190), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already have administrator-level access and to socially engineer another administrator into triggering the forged request (Feedly, GitHub PR).
group_id parameter to the desired value.group_id modification is persisted, altering the Anti-Spam Allowlist Group settings without proper authorization (Feedly, GitHub PR).group_id values or originating from unexpected IP addresses.Upgrade Concrete CMS to version 9.4.8 or later, which resolves this vulnerability by ensuring CSRF token validation occurs before configuration changes are saved. The patch is available via the official 9.4.8 release and was merged in GitHub pull request #12826. As an interim measure, restrict administrative access to Anti-Spam Allowlist Group Configuration settings to trusted personnel only, and implement network-level controls to limit access to sensitive administrative functions (ConcreteCMS Release Notes, GitHub PR).
The vulnerability was acknowledged by the Concrete CMS security team, who assigned their own CVSS v4.0 score of 2.3 (Low), reflecting a more conservative severity assessment than the NVD's CVSS v3.1 score of 6.8 (Medium). The disclosure credited researcher z3rco for responsible reporting. No significant broader media coverage or notable researcher commentary beyond the official disclosure has been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."