CVE-2026-8140 | Concrete CMS up to 9.5.0 download cross-site request forgery
A vulnerability has been found in Concrete CMS up to 9.5.0 and classified as problematic. This affects the function Download of the file /dashboard/extend/install/download/. The manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2026-8140. The attack can be initiated remotely. There is not any exploit available.