Authorization Flaw in Concrete CMS Affects Page Reordering by Unauthorized Users
CVE-2026-81922

2.1LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-81922?

Concrete CMS versions prior to 9.5.3 contain an authorization vulnerability that allows authenticated users to manipulate page display orders within the sitemap without the necessary permissions. This flaw occurs due to a failure to enforce per-page authorization when using the send_to_top and send_to_bottom functions. As a result, users lacking edit or arrange rights on specific pages can alter the site's navigation structure, leading to potential misinformation and user navigation issues. A prompt update to version 9.5.3 or later is recommended to address this issue effectively.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dogeshark
.