CVE-2026-81924
Analyzed Analyzed - Analysis Complete

Cross-Site Request Forgery in Concrete CMS

Vulnerability report for CVE-2026-81924, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: ConcreteCMS

Description

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-supplied pageTemplates[] values without validating an anti-CSRF token.A remote attacker could host a page that auto-submitted a forged POST request; when a signed-in administrator visited it, the request executed under the administrator's session and created theme page-template records, changing site configuration without the administrator's consent.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions before 9.5.3 have a Cross-Site Request Forgery (CSRF) vulnerability in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action allows creating PageTemplate records from attacker-supplied values without validating an anti-CSRF token. This lets a remote attacker trick an administrator into executing a forged POST request that changes site configuration without consent.

Detection Guidance

This vulnerability involves a CSRF flaw in Concrete CMS theme page-template activation. Detection requires checking for unauthorized PageTemplate records created without admin consent. Inspect server logs for POST requests to /dashboard/themes/inspect/activate_files with pageTemplates[] parameters. Look for admin session tokens in requests without anti-CSRF tokens.

Impact Analysis

An attacker could exploit this to modify your Concrete CMS site's theme page-templates without your knowledge. This could change the site's appearance, functionality, or settings, potentially disrupting operations or exposing sensitive data if the attacker gains control over parts of the site.

Compliance Impact

This vulnerability could lead to unauthorized changes in site configuration, potentially violating compliance requirements that mandate strict access controls and audit trails for modifications. However, the CVSS score of 2.1 indicates low impact, so direct compliance violations may be limited unless combined with other issues.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to address the CSRF vulnerability in the theme page-template activation feature.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81924. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart