PatchSiren cyber security CVE debrief
CVE-2026-18424 Concrete CMS CVE debrief
A low-privileged authenticated user in Concrete CMS versions 9.0.0 to 9.5.2 can exploit a Server-Side Request Forgery (SSRF) vulnerability via cross-port reuse of a host's validated DNS pin, allowing them to import files and potentially access internal resources. The vulnerability arises from the reuse of a host's validated DNS pin for multiple remote URLs, which can lead to unauthorized access to internal resources. Concrete CMS administrators and security teams should assess exposure and prioritize remediation for instances with untrusted users.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-20
Who should care
Concrete CMS administrators and security teams should assess exposure and prioritize remediation for instances with untrusted users. They should verify Concrete CMS version and apply patches if available, monitor for suspicious file import activity, and review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
A low-privileged authenticated user in Concrete CMS versions 9.0.0 to 9.5.2 can exploit a Server-Side Request Forgery (SSRF) vulnerability via cross-port reuse of a host's validated DNS pin, allowing them to import files and potentially access internal resources.
- Potential access to internal resources
- Possible data leakage or unauthorized actions
- Need for verification of affected versions and patch application
- Potential for DNS rebinding attacks
Technical summary
The vulnerability is caused by the reuse of a host's validated DNS pin for multiple remote URLs, allowing a low-privileged authenticated user to import files and potentially access internal resources. This can lead to potential access to internal resources, possible data leakage or unauthorized actions, and the need for verification of affected versions and patch application. The vulnerability has a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. Concrete CMS administrators and security teams should assess exposure and prioritize remediation for instances with untrusted users.
Defensive priority
Assess exposure and prioritize remediation for Concrete CMS instances with untrusted users.
Recommended defensive actions
- Assess exposure and prioritize remediation for Concrete CMS instances with untrusted users
- Verify Concrete CMS version and apply patches if available
- Monitor for suspicious file import activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability allows a low-privileged authenticated user to supply a DNS-rebinding host that resolves to a public address during validation and to a private or loopback address during the unpinned download, potentially causing the server to fetch internal-only resources. This can lead to potential access to internal resources, possible data leakage or unauthorized actions, and the need for verification of affected versions and patch application.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18424 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18424
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18424 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18424
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.