Unauthorized Access Vulnerability in Concrete CMS by Concrete Solutions
CVE-2026-81909
What is CVE-2026-81909?
Concrete CMS versions 9 through 9.5.2 exhibit a vulnerability related to Missing Authorization in the block alias route. This flaw allows users with limited permissions to access and manipulate blocks they should not have control over. Specifically, it fails to ensure that a block is legitimately orphaned and does not verify the caller's permissions over the source block. Consequently, a user with area-scoped permissions can duplicate content from any block on the site to areas they control, leading to unauthorized content exposure. The original content may also be deleted in the process, resulting in potential data loss. This vulnerability highlights the need for stricter authorization checks to prevent exploitation.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.2
