LOWVulnerability

CVE-2026-7888

Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for independently reporting the original components, and sh4d0byss for reporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/ VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.

Properties

epss_score
0.00175
cve_id
CVE-2026-7888
signal_observed_at
2026-09-11T21:54:06+00:00
published_at
2026-06-03T19:16:38.910
last_modified
2026-09-11T20:18:54.320
epss_percentile
0.07081

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Deserialization of Untrusted Data

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7888 — Ninja Signal Threat Intelligence | Ninja Signal