PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81903 Concrete CMS CVE debrief

A Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions 9.0.0 to 9.5.2. A user with access to the Page Containers dashboard can store a crafted icon value that, when viewed by another editor or administrator, can execute script in their authenticated session, potentially leading to session token theft and unauthorized dashboard actions.

Vendor
Concrete CMS
Product
Unknown
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-18
Advisory published
2026-09-14
Advisory updated
2026-09-18

Who should care

Defenders responsible for Concrete CMS installations, particularly those with user-delegated access to the Page Containers dashboard, should assess exposure and prioritize remediation to prevent potential session token theft and unauthorized dashboard actions.

Why it matters

Defenders should care about CVE-2026-81903 because it allows an attacker with access to the Page Containers dashboard to store a crafted icon value that can execute script in the authenticated session of another editor or administrator, potentially leading to session token theft and unauthorized dashboard actions. This vulnerability requires verification of exposure, assessment of user access controls, and application of vendor patches or workarounds to prevent exploitation.

  • Session token theft through XSS exploitation
  • Unauthorized dashboard actions by attackers
  • Potential for privilege escalation
  • Verification of user access controls and input validation

Technical summary

The vulnerability exists due to the lack of validation and encoding of user-submitted Page Container icon values. An attacker with access to the Page Containers dashboard can store a crafted icon value that breaks out of the src attribute and executes script in the authenticated session of another editor or administrator who views the list. This allows for potential session token theft and unauthorized dashboard actions. The vulnerability requires verification of exposure, assessment of user access controls, and application of vendor patches or workarounds to prevent exploitation.

Defensive priority

Defenders should prioritize verifying exposure, assessing user access to the Page Containers dashboard, and applying vendor patches or workarounds to prevent exploitation.

Recommended defensive actions

  • Verify Concrete CMS version and assess exposure
  • Restrict access to the Page Containers dashboard
  • Apply patches or workarounds provided by Concrete CMS
  • Monitor for suspicious activity on the dashboard
  • Review compensating controls for exposed systems
  • Track exceptions and retest remediated assets
  • Check relevant monitoring, detection, and logs for exposed assets

Evidence notes

The vulnerability was reported by Andrew Gonzalez and assigned a CVSS v4.0 score of 7.0 by the Concrete CMS security team. The NVD entry is currently Analyzed. Defenders should verify exposure by checking their Concrete CMS version and assess user access to the Page Containers dashboard. Evidence limits suggest verifying dashboard access controls and input validation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81903 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81903

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81903 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81903

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.