CVE-2026-8428 | Concrete CMS up to 9.5.0 local_available_update.php do_update token cross-site request forgery
A vulnerability described as problematic has been identified in Concrete CMS up to 9.5.0. Affected by this vulnerability is the function do_update of the file local_available_update.php. Such manipulation of the argument token leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-8428. It is possible to launch the attack remotely. No exploit is available.