CVE-2026-18425
Analyzed Analyzed - Analysis Complete

Concrete CMS Dashboard Sitemap Reorder Permission Bypass

Vulnerability report for CVE-2026-18425, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: ConcreteCMS

Description

Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each page's display order. As a result, an authenticated user granted sitemap access could change the display order (cDisplayOrder) of any pages they had no rights to edit, altering the order in which those pages render in navigation, breadcrumb, and page-list output. The reorder action additionally validated no CSRF token, so the write could be triggered by a forged request.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms From 9.0.0 (inc) to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS 9 before 9.5.3 allowed authenticated users with sitemap access to reorder pages without checking edit permissions. This could let them change the display order of pages they couldn't edit, affecting navigation and breadcrumb rendering. The action also lacked CSRF protection, enabling forged requests.

Detection Guidance

This vulnerability requires checking Concrete CMS dashboard permissions and sitemap reorder actions. Review user roles with sitemap access for unauthorized page order changes. Check server logs for suspicious POST requests to /dashboard/sitemap/update without CSRF tokens.

Impact Analysis

An attacker with sitemap access could rearrange pages in navigation menus or breadcrumbs, potentially exposing sensitive pages or hiding important ones. This could mislead users or disrupt normal site functionality.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it involves unauthorized page reordering in Concrete CMS without affecting data confidentiality, integrity, or availability of personal or health information. The issue is limited to navigation display order manipulation.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to address the vulnerability. Ensure that per-page edit permissions are properly checked before allowing sitemap reorder actions. Implement CSRF token validation for all sensitive actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18425. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart