Description
Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, so a state-changing group move could be processed for an authenticated user who did not initiate it. Because relocating a group under a new parent causes that group's members to inherit the parent's permissions, a forged move can change effective authorization. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-11
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery enabling unauthorized group relocation and permission changes
Action: Apply patch
AI Analysis

Impact

Concrete CMS versions before 9.5.3 are vulnerable to a Cross‑Site Request Forgery flaw in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint accepts a group move request without validating an action token. An attacker request that a logged‑in user unknow to be relocated under a new parent. Because child groups inherit the new parent’s permissions, this move can effectively alter the authorization for all users in those groups.

Affected Systems

Concrete CMS installations running any version earlier than 9.5.3 are affected. The flaw resides in the Move Multiple Groups functionality accessed via the dashboard users groups bulk update confirmation endpoint.

Risk and Exploitability

The CVSS v4.0 score of 5.7 reflects moderate severity. The flaw requires an authenticated user session and a simple HTTP request; it is a classic CSRF misuse. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would likely embed a malicious request in a thirding the user’s browser into moving group nodes and thereby changing group permissions without authorization.

Generated by OpenCVE AI on September 21, 2026 at 03:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version the CSRF protection fix
  • Configure the web valid CSRF token, ensuring any custom code also implements token checks
  • Disable or restrict the Move Multiple Groups feature for users who do not require group management rights if an immediate upgrade is not possible

Generated by OpenCVE AI on September 21, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


Sat, 12 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, so a state-changing group move could be processed for an authenticated user who did not initiate it. Because relocating a group under a new parent causes that group's members to inherit the parent's permissions, a forged move can change effective authorization. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:36:31.197Z

Reserved: 2026-08-27T18:21:25.200Z

Link: CVE-2026-81912

cve-icon Vulnrichment

Updated: 2026-09-11T19:36:26.374Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T20:19:13.950

Modified: 2026-09-24T20:18:47.767

Link: CVE-2026-81912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:30:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)