Description
Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore permanently delete, with no undo, or rename saved search presets owned by Express entities for which they had no permission, and a renamed preset name was displayed back to users of the targeted entity, enabling defacement or social engineering. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yalguun Tumenkhuu ( fg0x0 ) for reporting.
Published: 2026-09-15
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: Authorization bypass leading to deletion and defacement of search presets
Action: Assess Impact
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 allow an authenticated user to delete or rename Express saved search presets that belong to other entities. The vulnerability arises from insecure direct object reference, granting an attacker the ability to tamper with configuration data and display altered preset names to other users, which can be used for defacement or social engineering. This is a CWE‑639 vulnerability that affects the integrity of saved search data.

Affected Systems

The affected product is Concrete CMS by Concrete CMS, specifically versions 9.0.0 to 9.5.2 inclusive. Any deployments running within that version range are susceptible to the IDOR flaw in the Express saved search preset delete and edit dialogs.

Risk and Exploitability

The CVSS score of 2.1 indicates low overall severity, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data. Because it requires an authenticated user with at least view permission on one Express entity, an attacker does not need elevated privileges. The flaw can be exploited by navigating to the Express preset interface and issuing delete or rename actions on preset identifiers that the user does not own, leading to permanent removal or misleading information presented to other users. The lack of an EPSS score means current prediction of exploitation probability is unavailable, but the low score and limited exposure reduce immediate risk to most installations.

Generated by OpenCVE AI on September 15, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install the latest Concrete CMS release that addresses the IDOR flaw in Express search presets.
  • Restrict view permissions on Express entities to only users who truly need them, reducing the attack surface for IDOR.
  • Audit existing saved search presets for unexpected deletions or renames and revert any changes that are not authorized.
  • Monitor logs for repeated attempts to delete or rename presets on entities by users lacking ownership.
  • If a patch is not yet available, consider disabling the Express search preset functionality or segregating it behind tighter access controls.

Generated by OpenCVE AI on September 15, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore permanently delete, with no undo, or rename saved search presets owned by Express entities for which they had no permission, and a renamed preset name was displayed back to users of the targeted entity, enabling defacement or social engineering. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yalguun Tumenkhuu ( fg0x0 ) for reporting.
Title Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search pres
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:43:02.167Z

Reserved: 2026-07-30T18:16:57.546Z

Link: CVE-2026-18423

cve-icon Vulnrichment

Updated: 2026-09-15T19:42:58.328Z

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:09.800

Modified: 2026-09-15T20:17:09.800

Link: CVE-2026-18423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key