{"id":"CVE-2026-7888","summary":"Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.","details":"Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()\ncalls in the Workflow, Form block, and File/Set components that lack the\nallowed_classes restriction. The Form block and File/Set sinks were addressed in\n9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated\nattacker may trigger arbitrary PHP object instantiation if a malicious serialized\npayload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan\n(dizconnect) for independently reporting the original components, and sh4d0byss for\nreporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this\nvulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/\nVC:H/VI:H/VA:H/SC:N/SI:N/SA:N.","aliases":["GHSA-52pr-7vmf-2w7x"],"modified":"2026-09-13T03:30:59.238040568Z","published":"2026-06-03T18:10:10.917Z","database_specific":{"cna_assigner":"ConcreteCMS","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7888.json"},"references":[{"type":"ADVISORY","url":"https://documentation.concretecms.org/9-x/developers/introduction/version-history/952-release-notes"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7888.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7888"},{"type":"PACKAGE","url":"https://github.com/concretecms/concretecms"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/concretecms/concretecms","events":[{"introduced":"0"},{"last_affected":"8fe9708072c3815a5df719b592e4b23b43b4ff7a"}],"database_specific":{"extracted_events":[{"introduced":"5.0"},{"last_affected":"9.5.2"}],"source":"AFFECTED_FIELD"}}],"versions":["9.5.2","9.5.1","9.5.0","9.5.0RC2","9.5.0RC1","9.4.4","9.4.3","9.4.2","9.4.1","9.4.0","9.4.0RC2","9.4.0RC1","9.3.7","9.3.6","9.3.5","9.3.0","9.3.4","9.3.3","9.3.2","9.3.1","8.4.1","8.3.1","8.2.1","8.2.0","8.2.0RC2","8.1.0","5.7.5.7","5.7.5.6","5.7.5.5","5.7.5.2","5.7.4.1","5.7.3.1","5.7.3","5.7.2.1","5.7.2","5.7.0.4","5.7.1","5.7.0.3","5.7.0.1","5.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7888.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}