Authorization Check Bypass in Concrete CMS by Concrete5
CVE-2026-81916
5.1MEDIUM
What is CVE-2026-81916?
A vulnerability exists in Concrete CMS versions prior to 9.5.3 that allows an authorized user to bypass the authorization checks for entry submissions. This occurs because the permission validation erroneously checks entries against the posted form entity, rather than the entity specified by the dashboard route. Consequently, users can create entries in unauthorized Express objects, which may lead to data corruption, unauthorized workflow triggers, or malicious content injection into admin processes. This flaw can significantly compromise the integrity and security of protected datasets.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
