CVE-2026-81922
Received Received - Intake

Authorization Bypass in Concrete CMS Page Reordering

Vulnerability report for CVE-2026-81922, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-18

Assigner: ConcreteCMS

Description

Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the sitemap Explore dashboard controller, the send_to_top and send_to_bottom reorder tasks ran after only a generic sitemap-access check; the controller loaded the page named by the attacker-controlled cNodeID parameter and changed its display order without verifying that the current user held move or arrange permission on that specific page. Because of this, an authenticated user who could reach the sitemap but had no edit or arrange rights on a given page could still move that page and alter the site's global navigation order.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-18
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions before 9.5.3 had a flaw in the sitemap Explore dashboard where authenticated users could reorder pages without proper authorization. The system only checked for generic sitemap access before allowing page reordering via send_to_top or send_to_bottom tasks. This meant users without specific edit or arrange permissions on a page could still move it, altering the site's global navigation order.

Detection Guidance

This vulnerability requires checking Concrete CMS versions and reviewing sitemap access controls. First, verify if your Concrete CMS version is below 9.5.3. Then inspect sitemap permissions for users who can access the Explore dashboard but lack page-specific move or arrange rights. No direct commands are provided for detection.

Impact Analysis

An attacker with limited access could rearrange pages on your site, disrupting navigation and potentially misleading users. While the impact is low severity (CVSS 2.1), it could affect site usability and user trust if exploited.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards. The issue involves unauthorized page reordering in Concrete CMS, which is a content management system. There is no evidence in the provided context that this vulnerability leads to data breaches, unauthorized access to sensitive data, or violations of privacy regulations.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to address the authorization bypass in page reordering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81922. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart