CVE-2026-18426
Analyzed Analyzed - Analysis Complete

Stored XSS in Concrete CMS Express Form Block

Vulnerability report for CVE-2026-18426, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: ConcreteCMS

Description

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than to a specific block, page, or form, an authenticated user with edit access to one Express Form could reuse a validly obtained token to add, modify, or delete controls on Express Forms they were not authorized to edit, including injecting a control whose value is later rendered as HTML to achieve stored XSS.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yat Wu for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms From 9.0.0 (inc) to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 through 9.5.2 had a flaw where block-level edit permissions were not properly enforced for Express Form blocks. The system relied only on CSRF token validation, which is tied to the user and action but not to a specific block, page, or form. This allowed an authenticated user with edit access to one Express Form to reuse a valid token to modify other Express Forms they were not authorized to edit, potentially leading to stored cross-site scripting (XSS) via injected HTML controls.

Impact Analysis

An attacker with edit access to one Express Form could exploit this to alter other forms, inject malicious scripts, or manipulate form controls. This could lead to unauthorized data changes, data theft, or defacement of the website. The impact is limited by the CVSS score of 2.0, indicating low severity, but still poses risks to data integrity and user trust.

Compliance Impact

This vulnerability could lead to unauthorized data modifications or theft, which may violate GDPR (data protection) or HIPAA (healthcare data privacy) requirements. Compliance risks include potential data breaches, loss of user trust, and legal penalties due to insufficient access controls and inadequate protection against XSS attacks.

Mitigation Strategies

Update Concrete CMS to version 9.5.3 or later to address the block-level edit-permission issue. Review and restrict user permissions to ensure only authorized users can edit Express Forms. Monitor for unauthorized modifications or suspicious activity in Express Form controls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18426. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart