THREAT OPS › Threat News › [NVD] CVE-2026-68532 — Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group ty
[NVD] CVE-2026-68532 — Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group ty
CVE-2026-68532 CVSS: None Published: 2026-09-15T19:17:37.033
Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group type. The Concrete CMS security team gave this vulnerabilit
Indicators of compromise
- CVE-2026-68532cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68532