SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18423

LOW · CVSS 2.1 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Concrete CMS versions 9.0.0 through 9.5.2 are susceptible to an insecure direct object reference (IDOR) vulnerability, allowing authenticated users with only view permissions to delete or rename saved search presets of other users without authorization. This can lead to permanent loss of data and potential defacement or social engineering risks, as renamed presets are visible to users of the affected entities. Organizations using these versions should prioritize addressing this vulnerability to mitigate risks associated with unauthorized data manipulation.

CVE
CVE-2026-18423
Severity
LOW
CVSS
2.1
EPSS
0.28%

Original NVD Description

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore permanently delete, with no undo, or rename saved search presets owned by Express entities for which they had no permission, and a renamed preset name was displayed back to users of the targeted entity, enabling defacement or social engineering. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yalguun Tumenkhuu ( fg0x0 ) for reporting.