Description
Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each page's display order. As a result, an authenticated user granted sitemap access could change the display order (cDisplayOrder) of any pages they had no rights to edit, altering the order in which those pages render in navigation, breadcrumb, and page-list output. The reorder action additionally validated no CSRF token, so the write could be triggered by a forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Published: 2026-09-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Page order manipulation through improper authorization
Action: Assess Impact
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 allow an authenticated user with broad sitemap access to reorder any page’s display order. The backend endpoint, SitemapUpdate::updateDisplayOrder, relies only on a global sitemap flag and skips checking each target page’s edit permissions. Additionally, the action omits a CSRF token, so a forged request can trigger the write. The result is that a user who cannot edit certain pages can still change the order in which those pages appear in navigation menus, breadcrumbs, and page‑list output, potentially misleading visitors or altering the perceived structure of the site. The vulnerability does not grant code execution or data exfiltration but does expose a flaw in access control semantics for page ordering.

Affected Systems

Any installation of Concrete CMS version 9.0.0 up to and including 9.5.2 that has enabled the dashboard sitemap functionality. All such sites must be evaluated for the presence of the vulnerable reorder endpoint.

Risk and Exploitability

The CVSS score of 2.1 indicates a low impact rating. The EPSS score is reported as below 1 %, meaning the exploitation probability is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with sitemap permission, so it is constrained to internal or compromised accounts. Because the lack of a CSRF token allows a forged request, an attacker who can trick the victim into accessing a crafted URL could trigger the action from a remote context, but still must possess the necessary permission. Given the limited scope and low likelihood, the overall risk is minimal, but the issue demonstrates a weakness in authorization checks that can be abused by privileged users.

Generated by OpenCVE AI on September 20, 2026 at 11:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later, which corrects the access and CSRF checks.
  • Restrict the sitemap permission to trusted accounts only, limiting the pool of users who can trigger the reorder action.
  • Ensure that all admin endpoints require a valid CSRF token; if the platform does not enforce this, implement a CSRF guard as a temporary mitigant.
  • Review page permission settings to confirm that only intended users have edit rights, reducing the impact of any future ordering or similar flaws.

Generated by OpenCVE AI on September 20, 2026 at 11:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each page's display order. As a result, an authenticated user granted sitemap access could change the display order (cDisplayOrder) of any pages they had no rights to edit, altering the order in which those pages render in navigation, breadcrumb, and page-list output. The reorder action additionally validated no CSRF token, so the write could be triggered by a forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Title IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an authenticated sitemap user to reorder arbitrary pages
Weaknesses CWE-352
CWE-862
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-20T00:45:42.695Z

Reserved: 2026-07-30T18:16:59.345Z

Link: CVE-2026-18425

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:00.663Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:10.450

Modified: 2026-09-21T17:51:00.470

Link: CVE-2026-18425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:45:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization