Insecure Direct Object Reference in Concrete CMS by Concrete5
CVE-2026-18423

2.1LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-18423?

Concrete CMS versions 9.0.0 through 9.5.2 are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability in the Express saved search preset delete and edit dialogs. This flaw allows an authenticated user with only view permissions on a given Express entity to delete or rename saved search presets belonging to entities they do not have permission to access. As a result, renamed preset names can mislead users into social engineering or other forms of defacement, as the new names are visible to those interacting with the affected entities. Immediate action is recommended to safeguard sensitive data and prevent unauthorized access.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

fg0x0
.