Authorization Check Bypass in Concrete CMS by Concrete5
CVE-2026-81916

5.1MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-81916?

A vulnerability exists in Concrete CMS versions prior to 9.5.3 that allows an authorized user to bypass the authorization checks for entry submissions. This occurs because the permission validation erroneously checks entries against the posted form entity, rather than the entity specified by the dashboard route. Consequently, users can create entries in unauthorized Express objects, which may lead to data corruption, unauthorized workflow triggers, or malicious content injection into admin processes. This flaw can significantly compromise the integrity and security of protected datasets.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tenzai
.