Dashboard Sitemap Reorder Vulnerability in Concrete CMS by Concrete5
CVE-2026-18425
2.1LOW
What is CVE-2026-18425?
Concrete CMS versions below 9.5.3 contain a vulnerability that permits authenticated users with sitemap access to alter the display order of pages they aren't authorized to edit. This occurs due to insufficient validation of user permissions during the dashboard sitemap reorder action, which relies exclusively on a global access permission. Additionally, the lack of CSRF token validation means that these reorder actions could also be triggered via forged requests, further exposing the site to unauthorized modifications.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
