CVE-2026-18423
Analyzed Analyzed - Analysis Complete

Insecure Direct Object Reference in Concrete CMS

Vulnerability report for CVE-2026-18423, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: ConcreteCMS

Description

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore permanently delete, with no undo, or rename saved search presets owned by Express entities for which they had no permission, and a renamed preset name was displayed back to users of the targeted entity, enabling defacement or social engineering.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yalguun Tumenkhuu ( fg0x0 ) for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms From 9.0.0 (inc) to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 through 9.5.2 have an Insecure Direct Object Reference (IDOR) vulnerability in Express saved search preset delete and edit dialogs. An authenticated user with only view permission on one Express entity can permanently delete or rename saved search presets belonging to other Express entities without proper authorization. This could lead to data loss or social engineering attacks.

Detection Guidance

This vulnerability is specific to Concrete CMS versions 9.0.0 through 9.5.2 and involves Insecure Direct Object Reference (IDOR) in Express saved search preset features. Detection requires checking Concrete CMS versions and reviewing user permissions for Express entities. No direct network commands are provided in the context.

Impact Analysis

If you are an authenticated user with view permissions in Concrete CMS 9.0.0-9.5.2, an attacker with similar access could delete or rename your saved search presets. This may cause loss of important data or mislead users through defacement or social engineering tactics.

Compliance Impact

This vulnerability could impact compliance by enabling unauthorized data deletion or manipulation, potentially violating integrity and access control requirements in GDPR and HIPAA. However, the CVSS score of 2.1 suggests limited impact on confidentiality or availability.

Mitigation Strategies

Immediately update Concrete CMS to a version beyond 9.5.2 to address the IDOR vulnerability. Review and restrict user permissions to ensure only authorized users can modify Express saved search presets. Monitor for unauthorized changes or deletions of presets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18423. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart