Unknown · Concrete Cms · CVE-2026-18426
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions 9.0.0 through 9.5.2
**Description**
An issue exists where block-level edit-permission checks are not enforced on the Express Form block's control-management actions. The system relies exclusively on CSRF (Cross-Site Request Forgery) token validation, but since the token is bound to the user and action rather than a specific block, page, or form, it can be reused. An authenticated user with edit access to one Express Form can use a valid token to add, modify, or delete controls on other Express Forms they are not authorized to edit. This can lead to stored XSS (Cross-Site Scripting), where a malicious script is permanently stored on the server and executed in the browser of other users, by injecting a control whose value is rendered as HTML.
**Recommendations**
Update Concrete CMS to a version later than 9.5.2.