CVE-2026-81920
Received Received - Intake

Cross-Site Request Forgery in Concrete CMS Dashboard

Vulnerability report for CVE-2026-81920, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-18

Assigner: ConcreteCMS

Description

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did not validate the anti-CSRF token that the reset modal emitted, and it did not restrict the request to the POST method. A remote attacker who lured an authenticated user with SEO access to a crafted page could revert the reserved-word list to its default and silently alter future URL-slug generation for pages, files, topics, and other objects created through the Text urlify service, undoing the site's configured SEO slug policy.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-18
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions below 9.5.3 had a Cross-Site Request Forgery (CSRF) vulnerability in the dashboard SEO Excluded Words page. The reset() function allowed clearing the administrator-configured reserved-word list without validating the anti-CSRF token or restricting the request to POST method. This could let an attacker trick an authenticated user with SEO access into triggering the reset, reverting the reserved-word list to default settings.

Detection Guidance

This vulnerability is specific to Concrete CMS versions below 9.5.3 and involves a CSRF flaw in the SEO Excluded Words page. Detection requires checking the Concrete CMS version and reviewing access logs for suspicious POST requests to the reset() controller action in the dashboard SEO Excluded Words page.

Impact Analysis

An attacker could silently alter future URL-slug generation for pages, files, and other objects created through the Text urlify service. This would undo the site's configured SEO slug policy, potentially affecting search engine rankings and user navigation. The impact is limited due to the low CVSS score of 2.3.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA. The issue involves a CSRF flaw in Concrete CMS that could allow an attacker to reset SEO reserved words, potentially altering URL slug generation. However, there is no evidence this affects data protection, privacy controls, or security policies required by GDPR or HIPAA.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to patch the CSRF vulnerability. Additionally, review and restrict access to the SEO Excluded Words page in the dashboard to minimize exposure. Monitor for unauthorized changes to the reserved-word list.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81920. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart