CVE-2026-30662: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30662 is a Denial of Service (DoS) vulnerability in ConcreteCMS v9.4.7 affecting the File Manager component. The flaw resides in the download method of concrete/controllers/backend/file.php, which improperly manages memory when creating zip archives for bulk file downloads. It was published on March 24, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, PoC Report).

Technical details

The root cause is Uncontrolled Resource Consumption (CWE-400): the download method uses ZipArchive::addFromString combined with file_get_contents to build zip archives, loading the entire content of every selected file into PHP memory without any size or memory constraints. An authenticated attacker can trigger an Out-Of-Memory (OOM) condition by initiating a bulk download of large files via a crafted HTTP GET request to /index.php/ccm/system/file/download with multiple fID[] parameters. This causes the PHP-FPM worker process to terminate with a SIGSEGV signal, resulting in the web server returning a 500 error. No special privileges beyond a standard authenticated session are required (Feedly, PoC Report).

Impact

Successful exploitation causes the PHP-FPM process to crash, rendering the ConcreteCMS web application unavailable and returning HTTP 500 errors to all users. The impact is limited to availability — there is no confidentiality or integrity impact, and the vulnerability does not enable code execution or data exfiltration. Any authenticated user with access to the File Manager can repeatedly trigger this condition, potentially causing sustained service disruption (Feedly).

Exploitability

A public proof-of-concept (PoC) report with detailed reproduction steps and a specific HTTP request payload is available (PoC Report). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039% (very low probability of exploitation in the near term). Exploitation requires only a low-privilege authenticated account, lowering the barrier for abuse (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a ConcreteCMS v9.4.7 instance and obtain or register a low-privilege authenticated account with access to the File Manager.
  2. Upload large files: Log in to the ConcreteCMS dashboard, navigate to the File Manager, and upload one or more large files (e.g., multi-hundred MB files) to maximize memory consumption during the bulk download.
  3. Obtain a valid CSRF token: Retrieve a valid ccm_token from the ConcreteCMS session (e.g., by inspecting the File Manager page source or intercepting a legitimate request with a proxy tool like Burp Suite).
  4. Craft the malicious request: Send a GET request targeting the bulk download endpoint with multiple file IDs:
    GET /index.php/ccm/system/file/download?fID[]=10&fID[]=11&ccm_token=<csrf_token> HTTP/1.1
    Host: <target>
    Cookie: <session_cookie>
  5. Trigger OOM crash: The server loads all selected files into PHP memory simultaneously via file_get_contents, exhausting available memory, causing PHP-FPM to terminate (SIGSEGV), and the web server to return a 500 error.
  6. Repeat for sustained DoS: Repeat the request to keep crashing PHP-FPM workers, maintaining service unavailability (PoC Report, Feedly).

Indicators of compromise

  • Network: Repeated HTTP GET requests to /index.php/ccm/system/file/download with multiple fID[] parameters from the same authenticated session; HTTP 500 responses from the web server following these requests.
  • Logs: PHP-FPM error logs showing SIGSEGV or out of memory fatal errors; web server access logs with 500 status codes on the file download endpoint in rapid succession.
  • Process: PHP-FPM worker processes terminating unexpectedly; elevated memory usage by PHP-FPM workers immediately before crashes; repeated PHP-FPM process restarts visible in system process monitoring.
  • Application: ConcreteCMS becoming intermittently or persistently unavailable (HTTP 500) correlated with File Manager bulk download activity (PoC Report, Feedly).

Mitigation and workarounds

No official vendor patch has been specified in available data as of the time of this report. Recommended mitigations include: restricting File Manager bulk download functionality to users with elevated permissions only; enforcing PHP memory limits (memory_limit) and per-request file size caps in php.ini or PHP-FPM pool configuration; implementing rate-limiting or download quotas on the File Manager endpoint; and monitoring PHP-FPM processes for unexpected crashes with alerting on OOM conditions. Organizations should monitor the ConcreteCMS security advisories for an official patch release (Feedly).

Community reactions

The vulnerability was indexed by multiple vulnerability tracking platforms including VulDB, ENISA EUVD (EUVD-2026-14895), and INCIBE-CERT shortly after publication on March 24, 2026. No notable vendor statements or significant researcher commentary beyond the original PoC report have been identified (Feedly).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management