Description
Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any permission over the source block. A user granted only an area-scoped add_block_to_area delegation on their own page can therefore pass any block ID on the site: the source block's content is duplicated into an area the rogue editor controls, disclosing that content, and the original block is then force-deleted in the same request, destroying arbitrary site content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Integrity and Availability, content disclosure
Action: Upgrade
AI Analysis

Impact

Concrete CMS versions 9 through 9.5.2 contain a missing authorization flaw in the block alias endpoint. The code does not confirm that the target block is truly orphaned or that the caller has permission over the source block. An editor who can add blocks to their own page can repeatedly submit any block ID on the site; the system copies that block's content into the editor's area, revealing potentially sensitive data, and then force‑deletes the original block in the same HTTP request, destroying site content before any operation integrity compromise, and causing availability loss for arbitrary site blocks.

Affected Systems

Vulnerable systems are all installations of Concrete CMS running version 9 up to and including 9.5.2, as only those versions are impacted.

Risk and Exploitability

The CVSS score of 5.9 reflects a moderate severity with an attack vector reachable over the network, low authentication effort, and no user interaction. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The attacker must be an authenticated editorial user with add‑block‑to‑area rights on their own page, a relatively small privilege set. Because the flaw exists in the public web interface, there is no exploitation threshold beyond normal editorial access. Exploitation would involve the attacker submitting the block ID, duplicating the block into the editor's area, and deleting the source block in the same request. No publicly available exploit scripts are known, and the flaw is not listed in CISA KEV; confidentiality impact is low while integrity and availability impacts are high.

Generated by OpenCVE AI on September 21, 2026 at 05:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade when an official fix becomes available.
  • Restrict the add_block_to_area permission for editors, limiting their ability to create or manipulate blocks on any page.
  • Disable or remove the alias functionality from the backend interface until a fixed release is available.

Generated by OpenCVE AI on September 21, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any permission over the source block. A user granted only an area-scoped add_block_to_area delegation on their own page can therefore pass any block ID on the site: the source block's content is duplicated into an area the rogue editor controls, disclosing that content, and the original block is then force-deleted in the same request, destroying arbitrary site content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T17:58:35.013Z

Reserved: 2026-08-27T18:21:25.200Z

Link: CVE-2026-81909

cve-icon Vulnrichment

Updated: 2026-09-11T17:58:28.834Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T18:16:58.930

Modified: 2026-09-11T18:22:06.330

Link: CVE-2026-81909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:15:09Z

Weaknesses