Authorization Bypass in Concrete CMS Affects SEO Bulk Update Feature
CVE-2026-81923
2.1LOW
What is CVE-2026-81923?
In Concrete CMS versions prior to 9.5.3, the SEO Bulk Update Meta Tags editor improperly handled authorization, allowing users with limited permissions to modify meta titles, descriptions, and URL handles. This weakness arises from the failure to validate page edit permissions before executing save operations. As a consequence, unauthorized alterations to protected content were possible, potentially misleading users and affecting the integrity of website presentation.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
