Unauthorized Access Vulnerability in Concrete CMS by Concrete Solutions
CVE-2026-81909

5.9MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-81909?

Concrete CMS versions 9 through 9.5.2 exhibit a vulnerability related to Missing Authorization in the block alias route. This flaw allows users with limited permissions to access and manipulate blocks they should not have control over. Specifically, it fails to ensure that a block is legitimately orphaned and does not verify the caller's permissions over the source block. Consequently, a user with area-scoped permissions can duplicate content from any block on the site to areas they control, leading to unauthorized content exposure. The original content may also be deleted in the process, resulting in potential data loss. This vulnerability highlights the need for stricter authorization checks to prevent exploitation.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tenzai
.