Description
Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization but performed no token check, and its route accepted any HTTP method, so an attacker could induce a signed-in content editor into loading an attacker-controlled page that auto-submitted a cross-site request and reordered or moved blocks in the draft version of a page the victim was permitted to edit. The default null cookie SameSite configuration let the victim's session cookie accompany the forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Published: 2026-09-15
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross-Site Request Forgery resulting in unauthorized block reordering
Action: Patch
AI Analysis

Impact

Concrete CMS versions earlier than 9.5.3 allow a crafted request that does not require a valid anti-CSRF token to rearrange or move blocks within the draft version of a page. This flaw enables the attacker to exploit an authenticated editor’s session, causing the block arrangement to be altered without the editor’s consent. The vulnerability stems from missing CSRF validation, categorized as CWE-352.

Affected Systems

All installations of Concrete CMS running any release below 9.5.3 are vulnerable. The issue targets the block-arrangement backend endpoint in the arrange() action of Concrete\\Controller\\Backend\\Page\\ArrangeBlocks.

Risk and Exploitability

The flaw has a CVSS v4.0 score of 2.3, indicating low severity. The EPSS score is 0.00165, reflecting a very low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires a logged‑in content editor, a website that accepts the attacker’s manipulated request, and the default null SameSite cookie setting that allows the victim’s session cookie to be sent. The attacker can induce the editor to perform the action by loading a malicious page that auto‑submits a request, thereby moving or reordering blocks on a draft page.

Generated by OpenCVE AI on September 20, 2026 at 14:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Concrete CMS 9.5.3 or a later release that includes CSRF token validation on the block‑arrangement endpoint.
  • Configure the SameSite cookie attribute to "Lax" or "Strict" to prevent the victim’s session cookie from being sent with cross‑site requests.
  • Ensure that all backend endpoints handling state changes verify anti‑CSRF tokens before performing actions.

Generated by OpenCVE AI on September 20, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization but performed no token check, and its route accepted any HTTP method, so an attacker could induce a signed-in content editor into loading an attacker-controlled page that auto-submitted a cross-site request and reordered or moved blocks in the draft version of a page the victim was permitted to edit. The default null cookie SameSite configuration let the victim's session cookie accompany the forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Title Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arrangement Endpoint
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:25:36.719Z

Reserved: 2026-08-27T18:23:01.366Z

Link: CVE-2026-81919

cve-icon Vulnrichment

Updated: 2026-09-15T19:25:26.299Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:41.200

Modified: 2026-09-18T15:26:37.667

Link: CVE-2026-81919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)