THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-68532 — Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group ty

[NVD] CVE-2026-68532 — Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group ty

mednvdPublished 2026-09-15

CVE-2026-68532 CVSS: None Published: 2026-09-15T19:17:37.033

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group type. The Concrete CMS security team gave this vulnerabilit

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68532