Server-Side Request Forgery Vulnerability in Concrete CMS by Concrete5
CVE-2026-18424

2.1LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-18424?

A vulnerability in Concrete CMS versions 9.0.0 to 9.5.2 allows low-privileged authenticated users to exploit the Server-Side Request Forgery (SSRF) due to improper handling of validated DNS pins. This security flaw occurs when multiple remote URLs share the same host, causing only the first 'ValidatedRemoteUrl' to be used. This enables an attacker to craft a DNS-rebinding host during the validation process that resolves to a public address but reroutes to a private or loopback address during the unpinned download. Consequently, the server may inadvertently access internal services, admin panels, or cloud metadata endpoints, potentially compromising sensitive information stored within the server’s file manager.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lith004
.