PatchSiren cyber security CVE debrief
CVE-2026-18116 Concrete CMS CVE debrief
A stored cross-site scripting (XSS) vulnerability exists in Concrete CMS versions 8.3.0 to 9.5.2. A registered user with permission to add events to a calendar governed by an approval workflow can submit an event with a script payload. When an administrator views the pending request in the dashboard 'Waiting For Me' block, the script executes. This could be used to create a new administrator account.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-21
Who should care
Concrete CMS administrators, developers, and users with permission to add events to calendars with approval workflows should assess exposure and prioritize remediation. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impacts on their systems.
Why it matters
CVE-2026-18116 is a stored XSS vulnerability in Concrete CMS that allows an attacker to execute a script payload in an administrator's browser. Defenders should prioritize verifying and remediating this vulnerability, especially for Concrete CMS installations with user-submitted event functionality and approval workflows.
- An attacker could create a new administrator account
- An attacker could execute arbitrary scripts in an administrator's browser
- Defenders need to verify and remediate this vulnerability to prevent potential exploitation
- Defenders should monitor dashboard activity for suspicious requests
Technical summary
The vulnerability exists in Concrete CMS versions 8.3.0 to 9.5.2. A registered user permitted to add events to a calendar governed by an approval workflow could submit an event whose name contained a script payload. This payload executes in an administrator's browser when the pending request is displayed in the dashboard 'Waiting For Me' block. The vulnerability allows an attacker to execute a script payload in an administrator's browser, potentially leading to the creation of a new administrator account or other malicious activities.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially for Concrete CMS installations with user-submitted event functionality and approval workflows.
Recommended defensive actions
- Verify Concrete CMS version and apply patches or updates to remediate the vulnerability
- Restrict user permissions for adding events to calendars with approval workflows
- Monitor dashboard 'Waiting For Me' block for suspicious activity
- Review and update Concrete CMS configurations to prevent similar vulnerabilities
- Conduct regular security audits to identify potential issues
- Implement additional logging and monitoring for calendar event activities
- Ensure all administrators are aware of the vulnerability and its implications
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS v4.0 score of 7.3. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18116 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18116
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18116 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18116
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.