Authorization Flaw in Concrete CMS Affects Page Reordering by Unauthorized Users
CVE-2026-81922
2.1LOW
What is CVE-2026-81922?
Concrete CMS versions prior to 9.5.3 contain an authorization vulnerability that allows authenticated users to manipulate page display orders within the sitemap without the necessary permissions. This flaw occurs due to a failure to enforce per-page authorization when using the send_to_top and send_to_bottom functions. As a result, users lacking edit or arrange rights on specific pages can alter the site's navigation structure, leading to potential misinformation and user navigation issues. A prompt update to version 9.5.3 or later is recommended to address this issue effectively.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
