Server-Side Request Forgery Vulnerability in Concrete CMS by Concrete5
CVE-2026-18424
2.1LOW
What is CVE-2026-18424?
A vulnerability in Concrete CMS versions 9.0.0 to 9.5.2 allows low-privileged authenticated users to exploit the Server-Side Request Forgery (SSRF) due to improper handling of validated DNS pins. This security flaw occurs when multiple remote URLs share the same host, causing only the first 'ValidatedRemoteUrl' to be used. This enables an attacker to craft a DNS-rebinding host during the validation process that resolves to a public address but reroutes to a private or loopback address during the unpinned download. Consequently, the server may inadvertently access internal services, admin panels, or cloud metadata endpoints, potentially compromising sensitive information stored within the server’s file manager.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
