CVE-2026-68530
Received Received - Intake

Authorization Bypass in Concrete CMS Board Instances

Vulnerability report for CVE-2026-68530, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: ConcreteCMS

Description

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-supplied instance ID and then viewed, refreshed, regenerated, or deleted it without verifying that the requester held edit_board_settings on the instance's parent board. As a result, a user granted board-edit rights on a single board could reach the instances of any other board on the site by supplying their instance IDs. The affected actions bypassed the controller's permission-checked accessor (the same accessor used by the read view, which runs canEditBoardSettings on the parent board) and validated only an action-scoped CSRF token, which is bound to the action name rather than to the target object and is therefore reusable across boards.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concrete_cms concrete_cms From 9 (inc) to 9.5.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9 through 9.5.2 had a flaw where certain board-instance actions in the Dashboard did not check user authorization properly. An attacker with edit rights on one board could manipulate instance IDs to access, modify, or delete instances of other boards without proper permissions. The system failed to verify if the user had the required edit_board_settings permission on the parent board for these actions.

Detection Guidance

This vulnerability involves insufficient authorization checks in Concrete CMS versions 9 through 9.5.2. To detect it, inspect the Boards area in the Dashboard for unauthorized access to board instances. Check server logs for requests to board-instance actions with unexpected instance IDs. Verify if users with limited board-edit rights can access instances of other boards.

Impact Analysis

If you use Concrete CMS 9 through 9.5.2, an attacker with limited board-edit rights could potentially access or delete sensitive data from other boards on your site. This could lead to unauthorized changes, data loss, or exposure of confidential information across multiple boards.

Compliance Impact

This vulnerability could lead to unauthorized access or deletion of sensitive data, which may violate compliance requirements under GDPR (data protection) or HIPAA (healthcare data). Unauthorized changes to data could result in regulatory penalties or loss of certification.

Mitigation Strategies

Upgrade Concrete CMS to a version beyond 9.5.2 where this issue is patched. Review and restrict board-edit permissions to only necessary users. Monitor access logs for suspicious activity in the Boards area. Apply the latest security patches as soon as possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68530. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart