Description
Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on the target page, deleted every block on that page's current version; blocks not aliased to another page or scrapbook entry were also removed from the global Blocks table and their block-type data table, permanently destroying the content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data loss / Integrity
Action: Immediate Patch
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 contain a Cross‑Site Request Forgery vulnerability in the orphan block cleanup action. An attacker can craft a request that, when executed by an authenticated user with edit permission on its current version, removes every block on that page's current version; blocks not aliased to another page or scrapbook entry are also removed from the global Blocks table and their block‑type data table, permanently destroying the content. The vulnerability is a type of CSRF (CWE‑352) that results in data destruction without the need for code execution.

Affected Systems

Concrete CMS versions 9.0.0 through 9.5.2 are affected. No sub‑products or additional versions were identified in the advisory.

Risk and Exploitability

The CVE is scored 7.1 on CVSS‑high severity, and the EPSS score is <1%, indicating a very low likelihood of exploitation; it is not listed in CISA’s KEV catalog. The attack requires the victim to be an authenticated user with edit rights to the target page and the attacker to persuade that user to load a specially crafted request. This describes a classic CSRF scenario reflected in the UI:P vector component. Given the high CVSS score and the very low exploitability metric, the likelihood of exploitation is low, but the impact of content loss warrants a prompt response.

Generated by OpenCVE AI on September 20, 2026 at 21:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a patch or upgrade to Concrete CMS version newer than 9.5.2 that includes CSRF token validation for orphan block removal.
  • Restrict access to the orphan block cleanup panel to site administrators only, or disable the feature for non‑administrator users until a patch is available.
  • Implement logging or monitoring of orphan block removal actions so that any unexpected deletions can be detected and investigated promptly.

Generated by OpenCVE AI on September 20, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on the target page, deleted every block on that page's current version; blocks not aliased to another page or scrapbook entry were also removed from the global Blocks table and their block-type data table, permanently destroying the content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T14:23:57.270Z

Reserved: 2026-08-27T18:18:39.738Z

Link: CVE-2026-81902

cve-icon Vulnrichment

Updated: 2026-09-15T14:23:54.445Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:26.267

Modified: 2026-09-18T19:13:05.493

Link: CVE-2026-81902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:45:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)