Authorization Bypass in Concrete CMS Affects Multilingual Page Management
CVE-2026-18422
2.1LOW
What is CVE-2026-18422?
The vulnerability in Concrete CMS allows an authenticated user with 'Edit Page Multilingual Settings' permission to perform unauthorized actions in the multilingual page assignment backend. The absence of a destination-side authorization check and a validation failure for CSRF tokens pose significant risks, enabling manipulation of translation pairs across different locales. This can lead to unapproved page bindings and the potential deletion of essential translation data managed by other editors, disrupting the consistency of language routing on public-facing pages.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
