Junglewise Threat Intelligence

CVE-2026-18423: Concrete CMS insecure direct object reference in Express saved search presets

CVE-2026-18423 · Severity: high · CVSS 7.1 · Published 2026-09-15

Executive brief

Concrete CMS, a popular website content management platform, contains a flaw in how it controls access to saved search presets within its Express feature. An authenticated user with limited permissions can delete or rename saved search presets they shouldn't have access to, causing permanent data loss or defacing search results visible to other users. This allows attackers to disrupt workflow and potentially conduct social engineering attacks.

Technical details

This is an insecure direct object reference (IDOR) vulnerability in the Express saved search preset delete and edit dialogs. An authenticated user with only view permission on a single Express entity can exploit missing authorization checks to delete or rename saved search presets owned by other Express entities. The vulnerability affects versions 9.0.0 through 9.5.2. No user interaction is required; the attack is performed over the network by an authenticated attacker. A renamed preset name is returned to users of the targeted entity, enabling defacement or social engineering campaigns.

Affected products

  • Concrete CMS Concrete CMS 9.0.0 through 9.5.2

Timeline

  • 2026-09-15: disclosed

References

Related threats