Description
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Template Injection exposing secrets and server‑side request forgery
Action: Patch promptly
AI Analysis

Impact

Concrete CMS versions 9 through 9.5.2 contain a Server‑Side Template Injection flaw in the Theme Customizer. Style values entered through the customizer—such as color channels, font families, and image styles—are interpolated directly into server‑compiled LESS code without escaping or neutralization. An attacker who holds the Theme Customization permission can inject arbitrary LESS directives; for example, using the @import (inline) statement allows reading arbitrary files on the server and accessing internal network resources via PHP stream wrappers. The resulting compiled CSS is publicly cached, exposing the contents of any read files—including database credentials, private keys, and other secrets—through a site’s CSS cache, and it also enables server‑side request forgery.

Affected Systems

The affected product is Concrete CMS, specifically versions 9 through 9.5.2. The vulnerability involves the ColorStyle, FontFamilyStyle, ImageStyle, and related Style classes that process Theme Customizer input.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate risk, while an EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, meaning no widespread attacks are documented. Exploitation requires Theme Customization privilege, typically limited to administrators or users with similar roles. Once an attacker injects malicious LESS, the server compiles the style and writes it to the public CSS cache, exposing any disclosed file contents and permitting server‑side request forgery. Although the exploitation likelihood is low, the potential impact on confidentiality is high, so organizations running vulnerable installations should prioritize remediation.

Generated by OpenCVE AI on September 21, 2026 at 04:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later, where Style classes properly sanitize LESS syntax.
  • Restrict the Theme Customization permission to verified administrators only; regularly review users with that capability.
  • If an upgrade is not immediately possible, temporarily disable the Theme Customizer or block access to the CSS cache directory to prevent exposed secrets and monitor for suspicious activity.

Generated by OpenCVE AI on September 21, 2026 at 04:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Sat, 12 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values
Weaknesses CWE-1336
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:28:32.382Z

Reserved: 2026-08-27T18:21:25.200Z

Link: CVE-2026-81910

cve-icon Vulnrichment

Updated: 2026-09-11T19:28:26.783Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T19:17:46.610

Modified: 2026-09-16T17:40:45.243

Link: CVE-2026-81910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine