Description
Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission before generating page-backed summary content. As a result, an authenticated user holding edit-board-contents permission on a single board instance could submit the identifier of an item belonging to a different board instance and receive summary fields, including the page title and description, of an underlying page the same user was otherwise forbidden to view. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Pakung for reporting.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of restricted page metadata via an IDOR in the custom-slot preview that allows authenticated board editors to access titles and descriptions of pages they cannot normally view
Action: Apply Patch
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.3 did not validate that a board item submitted to the custom-slot preview endpoint belonged to the board the requesting user was authorized to edit, and it also did not enforce that the requester had permission to view the page that backs the summary content. This flaw is an Authorization bypass (CWE‑862) that lets an authenticated user holding the edit-board-contents privilege submit an identifier belonging to a different board instance and receive summary fields—including the page title and description—of an underlying page the user was otherwise denied to view.

Affected Systems

All concrete CMS deployments using edition 9.0.0 through 9.5.3, specifically those utilizing board modules with custom‑slot previews, are impacted. The issue surfaces when an authenticated user with editing rights submits a board item identifier that references a board outside the user’s authorized scope.

Risk and Exploitability

The vulnerability carries a CVSS v4.0 score of 5.3, indicating moderate impact. Its EPSS score is less than 1 %, denoting a very low current exploitation probability, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with edit-board-contents permission and knowledge of a valid item ID from another board instance. The attack does not require remote access or additional privileges beyond those already held by legitimate editors. Consequently, the overall risk level is moderate, and the likelihood of active exploitation is low at present.

Generated by OpenCVE AI on September 18, 2026 at 02:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Concrete CMS update that resolves the IDOR in the custom‑slot preview (any release after 9.5.3).
  • Restrict the edit-board-contents permission to the smallest set of trusted administrators and remove it from users who only need read access.
  • After applying the patch or tightening permissions, test the board preview endpoint with a non‑privileged user to confirm that page‑backed summary fields cannot be accessed from other board instances.

Generated by OpenCVE AI on September 18, 2026 at 02:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission before generating page-backed summary content. As a result, an authenticated user holding edit-board-contents permission on a single board instance could submit the identifier of an item belonging to a different board instance and receive summary fields, including the page title and description, of an underlying page the same user was otherwise forbidden to view. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Pakung for reporting.
Title Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-17T17:34:03.193Z

Reserved: 2026-09-08T18:06:45.237Z

Link: CVE-2026-87028

cve-icon Vulnrichment

Updated: 2026-09-17T17:33:52.423Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:16.560

Modified: 2026-09-21T17:51:39.373

Link: CVE-2026-87028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses