CVE-2026-81912 | Concrete CMS up to 9.5.2 Move Multiple Groups Feature confirm cross-site request forgery
A vulnerability was found in Concrete CMS up to 9.5.2 and classified as problematic. This impacts the function confirm of the file /users/groups/bulkupdate/confirm of the component Move Multiple Groups Feature. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is tracked as CVE-2026-81912. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More