
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30662 is a Denial of Service (DoS) vulnerability in ConcreteCMS v9.4.7 affecting the File Manager component. The flaw resides in the download method of concrete/controllers/backend/file.php, which improperly manages memory when creating zip archives for bulk file downloads. It was published on March 24, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, PoC Report).
The root cause is Uncontrolled Resource Consumption (CWE-400): the download method uses ZipArchive::addFromString combined with file_get_contents to build zip archives, loading the entire content of every selected file into PHP memory without any size or memory constraints. An authenticated attacker can trigger an Out-Of-Memory (OOM) condition by initiating a bulk download of large files via a crafted HTTP GET request to /index.php/ccm/system/file/download with multiple fID[] parameters. This causes the PHP-FPM worker process to terminate with a SIGSEGV signal, resulting in the web server returning a 500 error. No special privileges beyond a standard authenticated session are required (Feedly, PoC Report).
Successful exploitation causes the PHP-FPM process to crash, rendering the ConcreteCMS web application unavailable and returning HTTP 500 errors to all users. The impact is limited to availability — there is no confidentiality or integrity impact, and the vulnerability does not enable code execution or data exfiltration. Any authenticated user with access to the File Manager can repeatedly trigger this condition, potentially causing sustained service disruption (Feedly).
A public proof-of-concept (PoC) report with detailed reproduction steps and a specific HTTP request payload is available (PoC Report). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039% (very low probability of exploitation in the near term). Exploitation requires only a low-privilege authenticated account, lowering the barrier for abuse (Feedly).
ccm_token from the ConcreteCMS session (e.g., by inspecting the File Manager page source or intercepting a legitimate request with a proxy tool like Burp Suite).GET /index.php/ccm/system/file/download?fID[]=10&fID[]=11&ccm_token=<csrf_token> HTTP/1.1
Host: <target>
Cookie: <session_cookie>file_get_contents, exhausting available memory, causing PHP-FPM to terminate (SIGSEGV), and the web server to return a 500 error./index.php/ccm/system/file/download with multiple fID[] parameters from the same authenticated session; HTTP 500 responses from the web server following these requests.SIGSEGV or out of memory fatal errors; web server access logs with 500 status codes on the file download endpoint in rapid succession.No official vendor patch has been specified in available data as of the time of this report. Recommended mitigations include: restricting File Manager bulk download functionality to users with elevated permissions only; enforcing PHP memory limits (memory_limit) and per-request file size caps in php.ini or PHP-FPM pool configuration; implementing rate-limiting or download quotas on the File Manager endpoint; and monitoring PHP-FPM processes for unexpected crashes with alerting on OOM conditions. Organizations should monitor the ConcreteCMS security advisories for an official patch release (Feedly).
The vulnerability was indexed by multiple vulnerability tracking platforms including VulDB, ENISA EUVD (EUVD-2026-14895), and INCIBE-CERT shortly after publication on March 24, 2026. No notable vendor statements or significant researcher commentary beyond the original PoC report have been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."