PatchSiren cyber security CVE debrief
CVE-2026-81896 Concrete CMS CVE debrief
A stored cross-site scripting vulnerability exists in Concrete CMS versions prior to 9.5.3. An authenticated editor with high privileges could inject malicious HTML or script into form labels, which would then be executed in the browser of any administrator viewing the form submissions report. This issue was reported by Yonatan Drori from Tenzai and has been assigned a CVSS v4.0 score of 8.4.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-18
Who should care
Concrete CMS administrators, developers, and users with high privileges in the Dashboard, as well as security teams and vulnerability management teams responsible for assessing exposure and applying patches. Also, operators and platform teams who manage Concrete CMS deployments should be aware of this vulnerability and take necessary actions to mitigate it.
Why it matters
This stored cross-site scripting vulnerability in Concrete CMS versions prior to 9.5.3 requires attention from administrators and developers to assess exposure and apply patches, as it could lead to execution of malicious script in administrator browsers.
- Potential execution of malicious script in administrator browsers
- Possible data theft or unauthorized actions through administrator sessions
- Required verification of Concrete CMS versions and administrator privileges
- Necessity for prompt patching or updates to prevent exploitation
Technical summary
The vulnerability exists in the Dashboard Form Submissions report of Concrete CMS versions prior to 9.5.3, where user-defined Form block question labels are not properly encoded. This allows an authenticated editor with high privileges to inject malicious HTML or script, leading to stored cross-site scripting. The vulnerability has a CVSS v4.0 score of 8.4. The affected component is the Dashboard Form Submissions report, and the vulnerability class is stored cross-site scripting. The likely operational impact includes execution of malicious script in administrator browsers.
Defensive priority
High priority for Concrete CMS administrators and developers to assess exposure and apply patches
Recommended defensive actions
- Assess exposure by reviewing Concrete CMS versions and administrator privileges
- Apply patches or updates to Concrete CMS to address the vulnerability
- Monitor form submissions reports for suspicious activity
- Restrict editor privileges to prevent exploitation
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was reported by Yonatan Drori from Tenzai and has been documented in the CVE Program record and NVD vulnerability detail pages. The evidence provided is based on the CVE record and NVD detail page. The affected product is Concrete CMS versions prior to 9.5.3. The vulnerability exists in the Dashboard Form Submissions report, where user-defined Form block question labels are not properly encoded. This allows an authenticated editor with high privileges to inject malicious HTML or script. The CVSS v4.0 score is 8.4, as
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81896 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81896
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81896 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81896
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.