Dashboard Sitemap Reorder Vulnerability in Concrete CMS by Concrete5
CVE-2026-18425

2.1LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-18425?

Concrete CMS versions below 9.5.3 contain a vulnerability that permits authenticated users with sitemap access to alter the display order of pages they aren't authorized to edit. This occurs due to insufficient validation of user permissions during the dashboard sitemap reorder action, which relies exclusively on a global access permission. Additionally, the lack of CSRF token validation means that these reorder actions could also be triggered via forged requests, further exposing the site to unauthorized modifications.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

winstoncrooker
.