Description
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retained and reused for every later URL with that host. A low-privileged authenticated user permitted to import files could therefore supply a DNS-rebinding host that resolved to a public address during validation and to a private or loopback address during the unpinned download, causing the server to fetch internal-only resources such as loopback services, internal admin panels, or cloud metadata endpoints and to save the responses into the file manager. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. Thanks Ahmad Wicaksono (sonix03) for reporting.
Published: 2026-09-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Internal Resource Access via SSRF
Action: Update Software
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 are vulnerable to a server‑side request forgery (CWE‑918) that exploits cross‑port reuse of a host’s validated DNS pin during remote file import. The flaw allows a low‑privileged authenticated user to supply a DNS rebinding host that resolves to a public address during validation and to a private or loopback address during the actual download. The CMS then fetches and stores the private resources, such as internal admin panels or cloud metadata endpoints, into the file manager, exposing sensitive internal data to the attacker. The impact is limited to data exfiltration and unauthorized visibility of internal resources, not direct code execution.

Affected Systems

The affected vendor is Concrete CMS. Versions impacted are 9.0.0 up to and including 9.5.2. No additional version details are provided.

Risk and Exploitability

The CVSS score of 2.1 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated remote file import request originating from a user with limited privileges. Successful exploitation requires the attacker to control the DNS resolution of a host used in multiple import URLs, enabling the server to download internal resources hidden behind different ports. No known public exploits have been reported.

Generated by OpenCVE AI on September 20, 2026 at 12:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the remote file import feature or enforce a whitelist of trusted external domains.
  • Configure the web server to restrict outbound connections to internal IP ranges, limiting the ability of the CMS to reach internal services even if the SSRF flaw is exploited.
  • Check the vendor website for any official patch or update and apply when available.

Generated by OpenCVE AI on September 20, 2026 at 12:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retained and reused for every later URL with that host. A low-privileged authenticated user permitted to import files could therefore supply a DNS-rebinding host that resolved to a public address during validation and to a private or loopback address during the unpinned download, causing the server to fetch internal-only resources such as loopback services, internal admin panels, or cloud metadata endpoints and to save the responses into the file manager. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. Thanks Ahmad Wicaksono (sonix03) for reporting.
Title Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import when multiple URLs share a host but use different ports
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-20T00:45:42.836Z

Reserved: 2026-07-30T18:16:58.504Z

Link: CVE-2026-18424

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:04.245Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:10.310

Modified: 2026-09-21T17:50:50.450

Link: CVE-2026-18424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:15:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)