📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 8h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 9h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 13h Global malware Social Media and Consumer Technology HIGH 13h Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 8h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 9h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 13h Global malware Social Media and Consumer Technology HIGH 13h Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 8h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 9h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 13h Global malware Social Media and Consumer Technology HIGH 13h
Vulnerabilities

CVE-2026-8135

High
CWE-502 — Weakness Type
Published: May 21, 2026  ·  Modified: May 28, 2026  ·  Source: NVD
CVSS v3
7.2
🔗 NVD Official
📄 Description (English)

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF === true), which normally restricts malicious inputs over form POST requests, by leveraging the REST API functionality. Because the REST API parses requests using json_decode(), the string "true" is evaluated as a strict PHP Boolean(true).  This bypass allows the attacker to inject a malicious serialized payload  into the block's filterFields database column. The payload will subsequently be executed when the block's data is viewed or edited by an administrator leading to complete server takeover (RCE).The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.9 with a vector of CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H.  Thanks Nguyễn Văn Thiện https://github.com/Thien225409  for reporting

🤖 AI Executive Summary

Concrete CMS versions 9.5.0 and below contain a critical remote code execution vulnerability in the ExpressEntryList block controller. A rogue administrator can bypass security protections by exploiting insecure deserialization through the REST API, injecting malicious serialized payloads that execute when administrators view or edit blocks, leading to complete server compromise. This vulnerability requires administrative privileges but poses severe risk to organizations using Concrete CMS for content management.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 27, 2026 03:56
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using Concrete CMS for government portals, corporate websites, and content management systems face significant risk. Most vulnerable sectors include: Government agencies (NCA, MCIT) managing public information portals; Banking and financial institutions using CMS for customer-facing platforms; Healthcare organizations (MOH) managing patient information portals; Telecommunications companies (STC, Mobily) managing customer service portals; and Educational institutions. The vulnerability requires administrative access, making insider threats and compromised admin accounts critical concerns. Organizations with multiple administrators or third-party CMS management are at elevated risk.
🏢 Affected Saudi Sectors
Government Banking and Financial Services Healthcare Telecommunications Education Energy Media and Publishing
⚖️ Saudi Risk Score (AI)
8.1
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all Concrete CMS installations to identify version 9.5.0 and below
2. Review administrator account access logs for suspicious REST API activity, particularly POST requests to block-related endpoints
3. Restrict administrative access to only trusted personnel; disable unnecessary admin accounts
4. Monitor database for suspicious serialized payloads in block filterFields columns

PATCHING GUIDANCE:
1. Upgrade to Concrete CMS 9.5.1 or later when available (currently no patch released)
2. Until patch is available, implement compensating controls:
- Disable REST API endpoints for block management if not required
- Implement strict input validation on all block controller inputs
- Apply Web Application Firewall (WAF) rules to detect serialized PHP objects in requests

COMPENSATING CONTROLS:
1. Implement role-based access control (RBAC) limiting block creation/editing to essential personnel only
2. Enable detailed logging and monitoring of all block-related database modifications
3. Implement file integrity monitoring on Concrete CMS installation directories
4. Use PHP configuration to disable dangerous functions: disable_functions = unserialize, eval
5. Apply network segmentation to isolate CMS servers from critical infrastructure

DETECTION RULES:
1. Monitor for REST API requests containing 'O:' or 'a:' patterns (serialized object indicators) in POST bodies
2. Alert on any modifications to block filterFields column in database
3. Monitor for PHP execution from unexpected locations within CMS directories
4. Track administrator login patterns and REST API usage anomalies
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع تثبيتات Concrete CMS لتحديد الإصدار 9.5.0 وما دونه
2. مراجعة سجلات وصول حساب المسؤول للنشاط المريب في REST API، خاصة طلبات POST المتعلقة بنقاط نهاية الكتل
3. تقييد وصول المسؤول للموظفين الموثوقين فقط؛ تعطيل حسابات المسؤول غير الضرورية
4. مراقبة قاعدة البيانات للحمولات المسلسلة المريبة في أعمدة filterFields للكتل

إرشادات التصحيح:
1. الترقية إلى Concrete CMS 9.5.1 أو أحدث عند توفره (لا يوجد تصحيح حالياً)
2. حتى توفر التصحيح، تطبيق الضوابط البديلة:
- تعطيل نقاط نهاية REST API لإدارة الكتل إذا لم تكن مطلوبة
- تطبيق التحقق الصارم من المدخلات على جميع مدخلات متحكم الكتل
- تطبيق قواعد جدار الحماية (WAF) للكشف عن كائنات PHP المسلسلة في الطلبات

الضوابط البديلة:
1. تطبيق التحكم في الوصول القائم على الأدوار (RBAC) لتقييد إنشاء/تحرير الكتل للموظفين الأساسيين فقط
2. تفعيل السجلات التفصيلية ومراقبة جميع تعديلات قاعدة البيانات المتعلقة بالكتل
3. تطبيق مراقبة سلامة الملفات على دلائل تثبيت Concrete CMS
4. استخدام تكوين PHP لتعطيل الوظائف الخطرة: disable_functions = unserialize, eval
5. تطبيق تقسيم الشبكة لعزل خوادم CMS عن البنية التحتية الحرجة

قواعد الكشف:
1. مراقبة طلبات REST API التي تحتوي على أنماط 'O:' أو 'a:' (مؤشرات الكائن المسلسل) في أجسام POST
2. التنبيه على أي تعديلات على عمود filterFields للكتل في قاعدة البيانات
3. مراقبة تنفيذ PHP من مواقع غير متوقعة داخل دلائل CMS
4. تتبع أنماط تسجيل دخول المسؤول وشذوذ استخدام REST API
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies (administrative access restrictions) ECC 2024 A.8.2.1 - User Registration and Access Rights (privileged account management) ECC 2024 A.12.4.1 - Event Logging (monitoring of administrative actions) ECC 2024 A.12.6.1 - Management of Technical Vulnerabilities (patch management)
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Asset Management (inventory of CMS systems) SAMA CSF PR.AC-1 - Access Control (administrative privilege management) SAMA CSF DE.CM-1 - Detection and Analysis (monitoring for exploitation attempts) SAMA CSF RS.MI-2 - Incident Response (containment of compromised systems)
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access Control (privileged access management) ISO 27001:2022 A.8.22 - Information Security Incident Management ISO 27001:2022 A.8.32 - Change Management (patch deployment) ISO 27001:2022 A.8.33 - Management of Technical Vulnerabilities
🟣 PCI DSS v4.0.1
PCI DSS 2.4 - Configuration Standards (secure configuration of CMS) PCI DSS 6.2 - Security Patches (timely patching of vulnerabilities) PCI DSS 7.1 - Access Control (limiting administrative privileges) PCI DSS 10.2 - Logging and Monitoring (audit trails of administrative actions)
📦 Affected Products / CPE 1 entries
concretecms:concrete_cms
📊 CVSS Score
7.2
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredH — High
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.2
CWECWE-502
EPSS0.23%
Exploit No
Patch ✗ No
Published 2026-05-21
Source Feed nvd
🇸🇦 Saudi Risk Score
8.1
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-502
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.