CVE-2026-18422
Analyzed Analyzed - Analysis Complete

CSRF Token Bypass in Concrete CMS

Vulnerability report for CVE-2026-18422, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: ConcreteCMS

Description

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user who held the Edit Page Multilingual Settings permission on a single page could bind an arbitrary page in another locale as that source page's translation, and could delete legitimate translation pairs maintained by other editors, altering public-facing language routing across the site.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS before version 9.5.3 had a flaw in its multilingual page assignment feature. An authenticated user with the Edit Page Multilingual Settings permission could manipulate page translations by binding an arbitrary page in another language to a source page. This allowed them to delete legitimate translation pairs created by other editors, disrupting the site's language routing.

Detection Guidance

This vulnerability affects Concrete CMS versions before 9.5.3 and involves improper authorization checks in the multilingual page assignment feature. To detect it, check if your Concrete CMS version is below 9.5.3 by running commands like 'composer show concrete/concrete5' or checking the admin panel version info. Review page translation assignments for unauthorized changes or deletions in multilingual settings.

Impact Analysis

If exploited, this vulnerability could cause incorrect language versions of pages to be displayed to users, leading to misinformation or confusion. It could also disrupt the site's multilingual functionality by removing valid translations set by other editors.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it involves unauthorized page translation manipulation rather than data exposure or privacy violations. The issue is limited to content routing and does not involve protected health or personal data handling.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to address the authorization and CSRF token validation issues in the multilingual page assignment functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18422. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart