Description
Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in the registration flow, giving a second entry point on sites with registration enabled. Concrete CMS versions prior to 9.5.0 do not include the rcURL parameter or this allowlist and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Michal M. for reporting.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Apply Patch
AI Analysis

Impact

Concrete CMS versions 9.5.0 through 9.5.2 contain an Open Redirect flaw enabled by the rcURL parameter. When a user follows a link on the site’s own domain that includes this parameter, the application redirects the browser to an arbitrary external site immediately after authentication or registration. The consequence is phishing and credential theft, as the attacker can lure users to malicious sites that mimic legitimate ones. The vulnerability is a classic example of CWE‑601, which represents insecure redirects that can be abused for social engineering attacks.

Affected Systems

All installations of Concrete CMS running any of the following versions are affected: 9.5.0, 9.5.1, and 9.5.2. Versions prior to 9.5.0 do not expose the rcURL parameter and therefore are not vulnerable. The flaw occurs in both the authentication and registration flows, providing two potential entry points on sites that allow user registration.

Risk and Exploitability

The CVSS v4.0 score of 5.3 indicates moderate severity. The EPSS score of < 1% shows that the likelihood of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be user‐click; an attacker must craft a malicious link on the vulnerable site, and a victim must click that link, typically after login or registration, for the redirect to occur. No privilege escalation or remote code execution is required, but the social engineering impact can be significant if the victim is tricked into entering credentials at the target site.

Generated by OpenCVE AI on September 21, 2026 at 03:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later, which removes the rcURL parameter from the authentication and registration flows.
  • If an upgrade cannot be performed immediately, modify the application code or templates to validate the rcURL parameter against a strict allowlist of trusted domains, or remove the parameter entirely from the login and registration URLs.
  • After applying the fix or patch, test the login and registration pages to confirm that links containing the rcURL parameter no longer cause unexpected redirects.

Generated by OpenCVE AI on September 21, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Sat, 12 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in the registration flow, giving a second entry point on sites with registration enabled. Concrete CMS versions prior to 9.5.0 do not include the rcURL parameter or this allowlist and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Michal M. for reporting.
Title Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter.
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:36:02.510Z

Reserved: 2026-08-27T18:21:25.201Z

Link: CVE-2026-81913

cve-icon Vulnrichment

Updated: 2026-09-11T19:35:56.975Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T20:19:14.140

Modified: 2026-09-24T20:13:27.500

Link: CVE-2026-81913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')