PT-2026-93112 · Unknown · Concrete Cms

·

CVE-2026-18426

·

Published

2026-09-15

·

Updated

2026-09-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9.0.0 through 9.5.2
Description An issue exists where block-level edit-permission checks are not enforced on the Express Form block's control-management actions. The system relies exclusively on CSRF (Cross-Site Request Forgery) token validation, but since the token is bound to the user and action rather than a specific block, page, or form, it can be reused. An authenticated user with edit access to one Express Form can use a valid token to add, modify, or delete controls on other Express Forms they are not authorized to edit. This can lead to stored XSS (Cross-Site Scripting), where a malicious script is permanently stored on the server and executed in the browser of other users, by injecting a control whose value is rendered as HTML.
Recommendations Update Concrete CMS to a version later than 9.5.2.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18426

Affected Products

Concrete Cms