Authorization Bypass in Concrete CMS Affects SEO Bulk Update Feature
CVE-2026-81923

2.1LOW

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-81923?

In Concrete CMS versions prior to 9.5.3, the SEO Bulk Update Meta Tags editor improperly handled authorization, allowing users with limited permissions to modify meta titles, descriptions, and URL handles. This weakness arises from the failure to validate page edit permissions before executing save operations. As a consequence, unauthorized alterations to protected content were possible, potentially misleading users and affecting the integrity of website presentation.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dogeshark
.