PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81910 Concrete CMS CVE debrief

A Server-Side Template Injection (SSTI) vulnerability exists in Concrete CMS versions 9 through 9.5.2, specifically in the Theme Customizer. This allows users with Theme Customization permissions to inject arbitrary LESS directives by submitting unvalidated style values. The vulnerability can be exploited to read arbitrary files on the server, access internal network resources, and expose sensitive application secrets.

Vendor
Concrete CMS
Product
Unknown
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Concrete CMS administrators, security teams, and users with Theme Customization permissions should assess exposure and take necessary actions to mitigate the vulnerability. This includes reviewing and updating Concrete CMS to a secure version, restricting Theme Customization permissions, and monitoring for suspicious activity. Affected operators and platforms should prioritize patching and compensating controls.

Why it matters

This Server-Side Template Injection vulnerability in Concrete CMS allows users with Theme Customization permissions to inject arbitrary LESS directives, potentially leading to file disclosure, internal network access, and exposure of sensitive application secrets. Concrete CMS administrators and security teams should assess exposure and take necessary actions to mitigate the vulnerability.

  • Potential file disclosure and exposure of sensitive application secrets
  • Possible access to internal network resources through PHP stream wrappers
  • Risk of server-side request forgery
  • Need for verification of affected versions and remediation status

Technical summary

The vulnerability exists in the Theme Customizer of Concrete CMS versions 9 through 9.5.2. Unvalidated style values submitted by users with Theme Customization permissions can be interpolated into server-compiled LESS source without neutralization of LESS syntax. This allows for the injection of arbitrary LESS directives, potentially leading to file disclosure, internal network access, and exposure of sensitive application secrets.

Defensive priority

Medium priority for Concrete CMS administrators and security teams

Recommended defensive actions

  • Assess exposure by checking if Concrete CMS versions 9 through 9.5.2 are in use
  • Restrict Theme Customization permissions to trusted users
  • Monitor for suspicious LESS directive injections
  • Review and update Concrete CMS to a secure version if available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The vulnerability was reported by Yonatan Drori from Tenzai and assigned a CVSS v4.0 score of 5.9. The CVE Program and NVD provide official records and assessments of the vulnerability. This Server-Side Template Injection vulnerability in Concrete CMS allows users with Theme Customization permissions to inject arbitrary LESS directives, potentially leading to file disclosure, internal network access, and exposure of sensitive application secrets. Evidence is based on the CVE record and NVD detail page. Defenders should verify affected

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81910 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81910

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81910 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81910

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.