Description
Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than to a specific block, page, or form, an authenticated user with edit access to one Express Form could reuse a validly obtained token to add, modify, or delete controls on Express Forms they were not authorized to edit, including injecting a control whose value is later rendered as HTML to achieve stored XSS. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yat Wu for reporting.
Published: 2026-09-15
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass enabling unauthorized modification of Express Forms and stored XSS via primitive CSRF checks
Action: Apply Patch
AI Analysis

Impact

Concrete CMS versions between 9.0.0 and 9.5.2 omitted a block‑level permission check for the Express Form block’s control‑management operations. The controls’ actions are protected only by a CSRF token that is tied to the user and the specific action, not to the particular block, page or form. Consequently, an authenticated editor who has edit rights on one Express Form can reuse a valid CSRF token to add, modify or delete controls on other Express Forms for which they lack permission. By inserting a control whose value is rendered as raw HTML, the attacker can persist a cross‑site‑Scripting payload that will be executed whenever the form is processed or displayed. The weakness is an instance of unauthorized access to privileged capabilities (CWE‑862).

Affected Systems

The vulnerability affects Concrete CMS installations running versions 9.0.0 through 9.5.2. The problem is confined to the Express Form block functionality; any other components of the CMS are not directly impacted by the missing authorization check.

Risk and Exploitability

The CVSS v4 score of 2.0 indicates a low base severity, largely because an attacker must already possess a legitimate editor account. The EPSS probability of less than 1% suggests rare exploitation at the moment, and the vulnerability is not listed in the CISA KEV catalog. However, an attacker who can obtain or guess a valid editor’s CSRF token can elect to patch or modify the form’s controls remotely. Effective compromise requires accurate knowledge of the token, meaning the threat is primarily screen where the attacker can influence a logged‑in user or exploit session fixation. The absence of a hard block‑level check makes the vulnerability viable in scenarios where cross‑site request forgery is possible. Thus, while the risk rating remains low, any organizations using the affected CMS versions should still treat it as a risk that warrants remediation.

Generated by OpenCVE AI on September 18, 2026 at 14:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install Concrete CMS 9.5.3 or later to apply the vendor’s fix that restores block‑level authorization checks on Express Form control actions.
  • Restrict edit permissions for users who do not need to modify Express Forms, limiting the potential attack surface.
  • Sanitize and validate all form control values that are output as HTML to mitigate the possibility of stored XSS.

Generated by OpenCVE AI on September 18, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than to a specific block, page, or form, an authenticated user with edit access to one Express Form could reuse a validly obtained token to add, modify, or delete controls on Express Forms they were not authorized to edit, including injecting a control whose value is later rendered as HTML to achieve stored XSS. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yat Wu for reporting.
Title Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows an authenticated editor to modify Express Forms they cannot edit
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-16T17:51:16.894Z

Reserved: 2026-07-30T18:17:00.757Z

Link: CVE-2026-18426

cve-icon Vulnrichment

Updated: 2026-09-16T17:51:08.469Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T21:16:36.230

Modified: 2026-09-21T17:53:06.833

Link: CVE-2026-18426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:15:09Z

Weaknesses