CVE-2026-18424
Analyzed Analyzed - Analysis Complete

Server-Side Request Forgery in Concrete CMS via DNS Pinning Bypass

Vulnerability report for CVE-2026-18424, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: ConcreteCMS

Description

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retained and reused for every later URL with that host. A low-privileged authenticated user permitted to import files could therefore supply a DNS-rebinding host that resolved to a public address during validation and to a private or loopback address during the unpinned download, causing the server to fetch internal-only resources such as loopback services, internal admin panels, or cloud metadata endpoints and to save the responses into the file manager.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. Thanks Ahmad Wicaksono (sonix03) for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms From 9.0.0 (inc) to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 to 9.5.2 are vulnerable to Server-Side Request Forgery (SSRF) through cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first validated URL is reused for all subsequent URLs with that host. This allows a low-privileged authenticated user to import files via a DNS-rebinding attack, where a host resolves to a public address during validation but to a private or loopback address during download, causing the server to fetch internal resources.

Detection Guidance

Detecting this SSRF vulnerability in Concrete CMS requires checking for outdated versions (9.0.0 to 9.5.2) and monitoring file import functionality. Inspect server logs for unusual outbound requests to private or loopback addresses during file imports. Check if multiple remote URLs with the same host are processed sequentially, as this may indicate the DNS pinning bypass.

Impact Analysis

An attacker with low privileges could exploit this to make the server access internal services like loopback services, admin panels, or cloud metadata endpoints. The server would then save these responses into the file manager, potentially exposing sensitive internal data or enabling further attacks.

Compliance Impact

This vulnerability could lead to unauthorized access to internal systems, potentially exposing personal or sensitive data. This may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy), depending on the data accessed and the organization's policies.

Mitigation Strategies

Upgrade Concrete CMS to a version beyond 9.5.2 to address the SSRF vulnerability via DNS pinning bypass. Review file import permissions to ensure only trusted users can perform remote imports. Monitor network traffic for unusual internal requests originating from the CMS server.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18424. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart