Insecure Direct Object Reference in Concrete CMS by Concrete5
CVE-2026-18423
2.1LOW
What is CVE-2026-18423?
Concrete CMS versions 9.0.0 through 9.5.2 are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability in the Express saved search preset delete and edit dialogs. This flaw allows an authenticated user with only view permissions on a given Express entity to delete or rename saved search presets belonging to entities they do not have permission to access. As a result, renamed preset names can mislead users into social engineering or other forms of defacement, as the new names are visible to those interacting with the affected entities. Immediate action is recommended to safeguard sensitive data and prevent unauthorized access.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
