PatchSiren cyber security CVE debrief
CVE-2026-18423 Concrete CMS CVE debrief
A low-severity vulnerability was found in Concrete CMS versions 9.0.0 through 9.5.2, allowing an authenticated user with view permission on a single Express entity to delete or rename saved search presets owned by other entities. This could potentially enable defacement or social engineering. The vulnerability, caused by an Insecure Direct Object Reference (IDOR) in the Express saved search preset delete and edit dialogs, was reported by Yalguun Tumenkhuu (fg0x0) and scored 2.1 by the Concrete CMS security team with a CVSS v4.0 vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for Concrete CMS installations, particularly those with user-accessible Express entities, should assess exposure and verify affected versions. They should also consider updating to version 9.5.3 or later to prevent potential limited impact on saved search presets.
Why it matters
This low-severity vulnerability in Concrete CMS allows an authenticated user with limited permissions to modify saved search presets, potentially enabling defacement or social engineering. Defenders should verify affected versions, assess exposure, and consider updating to version 9.5.3 or later.
- An attacker could delete saved search presets, potentially disrupting user workflows.
- An attacker could rename saved search presets, potentially enabling social engineering or defacement.
- Defenders need to verify affected versions and assess exposure to prevent unauthorized modifications.
- Remediation priority is low but recommended to prevent potential limited impact.
Technical summary
The vulnerability is caused by an Insecure Direct Object Reference (IDOR) in the Express saved search preset delete and edit dialogs of Concrete CMS versions 9.0.0 through 9.5.2. An authenticated user with only view permission on a single Express entity can delete or rename saved search presets owned by other Express entities, potentially enabling defacement or social engineering. The vulnerability was reported by Yalguun Tumenkhuu (fg0x0) and scored 2.1 by the Concrete CMS security team with a CVSS v4.0 vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N.
Defensive priority
Defenders should prioritize verifying affected versions and assessing exposure, as the vulnerability allows for limited impact on saved search presets.
Recommended defensive actions
- Verify if the installed version of Concrete CMS is within the affected range (9.0.0 through 9.5.2) and update to version 9.5.3 or later if necessary.
- Restrict permissions for users with view access to Express entities to prevent unauthorized modifications to saved search presets.
- Monitor for any suspicious activity related to saved search presets, such as unexpected deletions or renames.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability was reported by Yalguun Tumenkhuu (fg0x0) and scored 2.1 by the Concrete CMS security team with a CVSS v4.0 vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18423 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18423
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18423 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18423
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.