PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81896 Concrete CMS CVE debrief

A stored cross-site scripting vulnerability exists in Concrete CMS versions prior to 9.5.3. An authenticated editor with high privileges could inject malicious HTML or script into form labels, which would then be executed in the browser of any administrator viewing the form submissions report. This issue was reported by Yonatan Drori from Tenzai and has been assigned a CVSS v4.0 score of 8.4.

Vendor
Concrete CMS
Product
Unknown
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-18
Advisory published
2026-09-15
Advisory updated
2026-09-18

Who should care

Concrete CMS administrators, developers, and users with high privileges in the Dashboard, as well as security teams and vulnerability management teams responsible for assessing exposure and applying patches. Also, operators and platform teams who manage Concrete CMS deployments should be aware of this vulnerability and take necessary actions to mitigate it.

Why it matters

This stored cross-site scripting vulnerability in Concrete CMS versions prior to 9.5.3 requires attention from administrators and developers to assess exposure and apply patches, as it could lead to execution of malicious script in administrator browsers.

  • Potential execution of malicious script in administrator browsers
  • Possible data theft or unauthorized actions through administrator sessions
  • Required verification of Concrete CMS versions and administrator privileges
  • Necessity for prompt patching or updates to prevent exploitation

Technical summary

The vulnerability exists in the Dashboard Form Submissions report of Concrete CMS versions prior to 9.5.3, where user-defined Form block question labels are not properly encoded. This allows an authenticated editor with high privileges to inject malicious HTML or script, leading to stored cross-site scripting. The vulnerability has a CVSS v4.0 score of 8.4. The affected component is the Dashboard Form Submissions report, and the vulnerability class is stored cross-site scripting. The likely operational impact includes execution of malicious script in administrator browsers.

Defensive priority

High priority for Concrete CMS administrators and developers to assess exposure and apply patches

Recommended defensive actions

  • Assess exposure by reviewing Concrete CMS versions and administrator privileges
  • Apply patches or updates to Concrete CMS to address the vulnerability
  • Monitor form submissions reports for suspicious activity
  • Restrict editor privileges to prevent exploitation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability was reported by Yonatan Drori from Tenzai and has been documented in the CVE Program record and NVD vulnerability detail pages. The evidence provided is based on the CVE record and NVD detail page. The affected product is Concrete CMS versions prior to 9.5.3. The vulnerability exists in the Dashboard Form Submissions report, where user-defined Form block question labels are not properly encoded. This allows an authenticated editor with high privileges to inject malicious HTML or script. The CVSS v4.0 score is 8.4, as

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81896 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81896

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81896 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81896

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.