PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18424 Concrete CMS CVE debrief

A low-privileged authenticated user in Concrete CMS versions 9.0.0 to 9.5.2 can exploit a Server-Side Request Forgery (SSRF) vulnerability via cross-port reuse of a host's validated DNS pin, allowing them to import files and potentially access internal resources. The vulnerability arises from the reuse of a host's validated DNS pin for multiple remote URLs, which can lead to unauthorized access to internal resources. Concrete CMS administrators and security teams should assess exposure and prioritize remediation for instances with untrusted users.

Vendor
Concrete CMS
Product
Unknown
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-20
Advisory published
2026-09-15
Advisory updated
2026-09-20

Who should care

Concrete CMS administrators and security teams should assess exposure and prioritize remediation for instances with untrusted users. They should verify Concrete CMS version and apply patches if available, monitor for suspicious file import activity, and review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

A low-privileged authenticated user in Concrete CMS versions 9.0.0 to 9.5.2 can exploit a Server-Side Request Forgery (SSRF) vulnerability via cross-port reuse of a host's validated DNS pin, allowing them to import files and potentially access internal resources.

  • Potential access to internal resources
  • Possible data leakage or unauthorized actions
  • Need for verification of affected versions and patch application
  • Potential for DNS rebinding attacks

Technical summary

The vulnerability is caused by the reuse of a host's validated DNS pin for multiple remote URLs, allowing a low-privileged authenticated user to import files and potentially access internal resources. This can lead to potential access to internal resources, possible data leakage or unauthorized actions, and the need for verification of affected versions and patch application. The vulnerability has a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. Concrete CMS administrators and security teams should assess exposure and prioritize remediation for instances with untrusted users.

Defensive priority

Assess exposure and prioritize remediation for Concrete CMS instances with untrusted users.

Recommended defensive actions

  • Assess exposure and prioritize remediation for Concrete CMS instances with untrusted users
  • Verify Concrete CMS version and apply patches if available
  • Monitor for suspicious file import activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability allows a low-privileged authenticated user to supply a DNS-rebinding host that resolves to a public address during validation and to a private or loopback address during the unpinned download, potentially causing the server to fetch internal-only resources. This can lead to potential access to internal resources, possible data leakage or unauthorized actions, and the need for verification of affected versions and patch application.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18424 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18424

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18424 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18424

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.