PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18116 Concrete CMS CVE debrief

A stored cross-site scripting (XSS) vulnerability exists in Concrete CMS versions 8.3.0 to 9.5.2. A registered user with permission to add events to a calendar governed by an approval workflow can submit an event with a script payload. When an administrator views the pending request in the dashboard 'Waiting For Me' block, the script executes. This could be used to create a new administrator account.

Vendor
Concrete CMS
Product
Unknown
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-21
Advisory published
2026-09-14
Advisory updated
2026-09-21

Who should care

Concrete CMS administrators, developers, and users with permission to add events to calendars with approval workflows should assess exposure and prioritize remediation. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impacts on their systems.

Why it matters

CVE-2026-18116 is a stored XSS vulnerability in Concrete CMS that allows an attacker to execute a script payload in an administrator's browser. Defenders should prioritize verifying and remediating this vulnerability, especially for Concrete CMS installations with user-submitted event functionality and approval workflows.

  • An attacker could create a new administrator account
  • An attacker could execute arbitrary scripts in an administrator's browser
  • Defenders need to verify and remediate this vulnerability to prevent potential exploitation
  • Defenders should monitor dashboard activity for suspicious requests

Technical summary

The vulnerability exists in Concrete CMS versions 8.3.0 to 9.5.2. A registered user permitted to add events to a calendar governed by an approval workflow could submit an event whose name contained a script payload. This payload executes in an administrator's browser when the pending request is displayed in the dashboard 'Waiting For Me' block. The vulnerability allows an attacker to execute a script payload in an administrator's browser, potentially leading to the creation of a new administrator account or other malicious activities.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability, especially for Concrete CMS installations with user-submitted event functionality and approval workflows.

Recommended defensive actions

  • Verify Concrete CMS version and apply patches or updates to remediate the vulnerability
  • Restrict user permissions for adding events to calendars with approval workflows
  • Monitor dashboard 'Waiting For Me' block for suspicious activity
  • Review and update Concrete CMS configurations to prevent similar vulnerabilities
  • Conduct regular security audits to identify potential issues
  • Implement additional logging and monitoring for calendar event activities
  • Ensure all administrators are aware of the vulnerability and its implications

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS v4.0 score of 7.3. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18116 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18116

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18116 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18116

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.