Authorization Bypass in Concrete CMS Affects Multilingual Page Management
CVE-2026-18422

2.1LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-18422?

The vulnerability in Concrete CMS allows an authenticated user with 'Edit Page Multilingual Settings' permission to perform unauthorized actions in the multilingual page assignment backend. The absence of a destination-side authorization check and a validation failure for CSRF tokens pose significant risks, enabling manipulation of translation pairs across different locales. This can lead to unapproved page bindings and the potential deletion of essential translation data managed by other editors, disrupting the consistency of language routing on public-facing pages.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

winstoncrooker
.