Description
Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditPageType(), so a signed-in dashboard user permitted to edit one Page Type could modify the configuration of Page Types outside their assigned authorization boundary. The update_page_type token was validated but is action- and user-scoped rather than object-scoped, so it did not constrain which Page Type could be targeted. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.
Published: 2026-09-11
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Concrete CMS versions older than 9.5.3 allow an authenticated dashboard user who has permission to edit a single Page Type to modify the configuration of any other Page Type. The flaw occurs because the Page Type update controller loads the target type by a user‑supplied identifier without calling the canEditPageType() authorization check. The update_page_type token is validated, but it is only action‑scoped, so it does not restrict which Page Type can be targeted. This bypass lets an authorized user extend their privileges to other Page Types, compromising the integrity of content structure and potentially enabling further attacks. The weakness is categorized as CWE-639 and CWE-862The CVSS v4.0 score of 5.1 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires a logged the ability to submit the update form, so the attack vector is primarily internal or through a compromised administrative account. Although the exploitation probability is low, the ability to modify configuration beyond authorized scope represents a significant internal risk for organizations using broad-ranging dashboard permissions.

Affected Systems

All installations of Concrete CMS running any version older than 9.5.3 are affected. The issue resides in the core CMS and is not limited to a specific module or add‑on.

Risk and Exploitability

Risk assessment indicates a moderate CVSS score of 5.1 and an EPSS probability of less than 1%, suggesting exploitation is unlikely but still possible. The lack of an Object‑level authorization check allows a malicious or misconfigured dashboard user to change the configuration of any Page Type they are not normally permitted to modify, escalating their operational impact within the CMS. Because the vulnerability requires the user to be authenticated and possess a valid edit‑page type token, the attack vector is internal or via a compromised administrative account, and the vulnerability is not recorded in CISA KEV.

Generated by OpenCVE AI on September 21, 2026 at 03:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Concrete CMS version 9.5.3 or later to restore the missing object‑level authorization check.
  • Limit dashboard users to only those who truly require Page Type edit access, reducing the attack surface for unauthorized configuration changes.
  • Conduct a security audit of existing Page Types to detect unintended modifications made before the patch and correct them.
  • If a vendor‑supplied hotfix is available, apply it immediately as a temporary barrier until the official release can be deployed.

Generated by OpenCVE AI on September 21, 2026 at 03:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditPageType(), so a signed-in dashboard user permitted to edit one Page Type could modify the configuration of Page Types outside their assigned authorization boundary. The update_page_type token was validated but is action- and user-scoped rather than object-scoped, so it did not constrain which Page Type could be targeted. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.
Title In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
Weaknesses CWE-639
CWE-862
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-14T13:00:32.395Z

Reserved: 2026-08-27T18:23:01.363Z

Link: CVE-2026-81915

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:46.496Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T20:19:14.290

Modified: 2026-09-24T20:07:18.440

Link: CVE-2026-81915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:30:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization