SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81909

MEDIUM · CVSS 5.9 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Concrete CMS versions 9 through 9.5.2 are vulnerable due to a missing authorization check in the block alias route, allowing users with limited permissions to manipulate block content across the site. This flaw enables unauthorized duplication and deletion of blocks, potentially leading to content disclosure and loss. Organizations using affected versions should prioritize patching this vulnerability to safeguard their content integrity and prevent unauthorized access.

CVE
CVE-2026-81909
Severity
MEDIUM
CVSS
5.9
EPSS
0.23%

Original NVD Description

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any permission over the source block. A user granted only an area-scoped add_block_to_area delegation on their own page can therefore pass any block ID on the site: the source block's content is duplicated into an area the rogue editor controls, disclosing that content, and the original block is then force-deleted in the same request, destroying arbitrary site content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.