Description
In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the per-page CSRF token but never called canEditPageProperties() for the target page, so a user who was granted access to the bulk SEO tool and could view (but not edit) a given page was able to change that page's meta title, meta description, and URL handle outside their edit scope, tampering with the presentation and live URLs of otherwise protected content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.
Published: 2026-09-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of page metadata
Action: Update CMS
AI Analysis

Impact

In Concrete CMS versions prior to 9.5.3 the SEO Bulk Update Meta Tags editor did not verify that a user had permission to edit page properties before saving changes. An attacker who could use the bulk SEO tool and view a page, but could not edit it, was able to alter the meta title, meta description, and URL handle of that page. This tampering changes the presentation and live URL of protected content.

Affected Systems

Concrete CMS concrete CMS versions earlier than 9.5.3. The vulnerability affects any installation where the bulk SEO tool is enabled and users have been granted bulk editing rights while lacking page edit permission.

Risk and Exploitability

The CVSS score of 2.1 indicates low severity. The EPSS score is <1% (approximately 0.23%), suggesting a very low likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is an internal user who has access to the bulk SEO tool; the attacker does not need to bypass network or authentication barriers. Exploitation therefore requires legitimate user privileges and knowledge of a page that can be edited visually but not in content. The impact is confined to page metadata rather than core functionality or critical assets.

Generated by OpenCVE AI on September 17, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later.
  • Restrict bulk SEO tool permissions to users who already have page edit rights or remove the tool for users with only view access.
  • Review and audit page metadata changes to detect unauthorized modifications.

Generated by OpenCVE AI on September 17, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the per-page CSRF token but never called canEditPageProperties() for the target page, so a user who was granted access to the bulk SEO tool and could view (but not edit) a given page was able to change that page's meta title, meta description, and URL handle outside their edit scope, tampering with the presentation and live URLs of otherwise protected content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.
Title Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editor
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:31:45.507Z

Reserved: 2026-08-27T18:23:01.367Z

Link: CVE-2026-81923

cve-icon Vulnrichment

Updated: 2026-09-15T19:31:41.779Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:41.733

Modified: 2026-09-16T19:16:15.097

Link: CVE-2026-81923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T09:00:17Z

Weaknesses