PatchSiren cyber security CVE debrief
CVE-2026-81903 Concrete CMS CVE debrief
A Cross-Site Scripting (XSS) vulnerability exists in Concrete CMS versions 9.0.0 to 9.5.2. A user with access to the Page Containers dashboard can store a crafted icon value that, when viewed by another editor or administrator, can execute script in their authenticated session, potentially leading to session token theft and unauthorized dashboard actions.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Concrete CMS installations, particularly those with user-delegated access to the Page Containers dashboard, should assess exposure and prioritize remediation to prevent potential session token theft and unauthorized dashboard actions.
Why it matters
Defenders should care about CVE-2026-81903 because it allows an attacker with access to the Page Containers dashboard to store a crafted icon value that can execute script in the authenticated session of another editor or administrator, potentially leading to session token theft and unauthorized dashboard actions. This vulnerability requires verification of exposure, assessment of user access controls, and application of vendor patches or workarounds to prevent exploitation.
- Session token theft through XSS exploitation
- Unauthorized dashboard actions by attackers
- Potential for privilege escalation
- Verification of user access controls and input validation
Technical summary
The vulnerability exists due to the lack of validation and encoding of user-submitted Page Container icon values. An attacker with access to the Page Containers dashboard can store a crafted icon value that breaks out of the src attribute and executes script in the authenticated session of another editor or administrator who views the list. This allows for potential session token theft and unauthorized dashboard actions. The vulnerability requires verification of exposure, assessment of user access controls, and application of vendor patches or workarounds to prevent exploitation.
Defensive priority
Defenders should prioritize verifying exposure, assessing user access to the Page Containers dashboard, and applying vendor patches or workarounds to prevent exploitation.
Recommended defensive actions
- Verify Concrete CMS version and assess exposure
- Restrict access to the Page Containers dashboard
- Apply patches or workarounds provided by Concrete CMS
- Monitor for suspicious activity on the dashboard
- Review compensating controls for exposed systems
- Track exceptions and retest remediated assets
- Check relevant monitoring, detection, and logs for exposed assets
Evidence notes
The vulnerability was reported by Andrew Gonzalez and assigned a CVSS v4.0 score of 7.0 by the Concrete CMS security team. The NVD entry is currently Analyzed. Defenders should verify exposure by checking their Concrete CMS version and assess user access to the Page Containers dashboard. Evidence limits suggest verifying dashboard access controls and input validation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81903 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81903
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81903 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81903
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.