PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18423 Concrete CMS CVE debrief

A low-severity vulnerability was found in Concrete CMS versions 9.0.0 through 9.5.2, allowing an authenticated user with view permission on a single Express entity to delete or rename saved search presets owned by other entities. This could potentially enable defacement or social engineering. The vulnerability, caused by an Insecure Direct Object Reference (IDOR) in the Express saved search preset delete and edit dialogs, was reported by Yalguun Tumenkhuu (fg0x0) and scored 2.1 by the Concrete CMS security team with a CVSS v4.0 vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N.

Vendor
Concrete CMS
Product
Unknown
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-21
Advisory published
2026-09-15
Advisory updated
2026-09-21

Who should care

Defenders responsible for Concrete CMS installations, particularly those with user-accessible Express entities, should assess exposure and verify affected versions. They should also consider updating to version 9.5.3 or later to prevent potential limited impact on saved search presets.

Why it matters

This low-severity vulnerability in Concrete CMS allows an authenticated user with limited permissions to modify saved search presets, potentially enabling defacement or social engineering. Defenders should verify affected versions, assess exposure, and consider updating to version 9.5.3 or later.

  • An attacker could delete saved search presets, potentially disrupting user workflows.
  • An attacker could rename saved search presets, potentially enabling social engineering or defacement.
  • Defenders need to verify affected versions and assess exposure to prevent unauthorized modifications.
  • Remediation priority is low but recommended to prevent potential limited impact.

Technical summary

The vulnerability is caused by an Insecure Direct Object Reference (IDOR) in the Express saved search preset delete and edit dialogs of Concrete CMS versions 9.0.0 through 9.5.2. An authenticated user with only view permission on a single Express entity can delete or rename saved search presets owned by other Express entities, potentially enabling defacement or social engineering. The vulnerability was reported by Yalguun Tumenkhuu (fg0x0) and scored 2.1 by the Concrete CMS security team with a CVSS v4.0 vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N.

Defensive priority

Defenders should prioritize verifying affected versions and assessing exposure, as the vulnerability allows for limited impact on saved search presets.

Recommended defensive actions

  • Verify if the installed version of Concrete CMS is within the affected range (9.0.0 through 9.5.2) and update to version 9.5.3 or later if necessary.
  • Restrict permissions for users with view access to Express entities to prevent unauthorized modifications to saved search presets.
  • Monitor for any suspicious activity related to saved search presets, such as unexpected deletions or renames.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability was reported by Yalguun Tumenkhuu (fg0x0) and scored 2.1 by the Concrete CMS security team with a CVSS v4.0 vector of CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18423 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18423

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18423 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18423

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.