Junglewise Threat Intelligence

CVE-2026-81901: Concrete CMS REST API authorization bypass in page update endpoint

CVE-2026-81901 · Severity: high · CVSS 8.7 · Published 2026-09-14

Technologies: Concrete CMS. Vendors: Concrete CMS.

Executive brief

Concrete CMS is a popular open-source content management system used to build and manage websites. A vulnerability in its REST API allows users with basic content-editing permissions to modify page properties, templates, and types—and crucially, to inject unescaped JavaScript into page headers that executes for all visitors, including administrators. An attacker could use this to steal credentials from reviewers or take over the site.

Technical details

The REST API endpoint PUT /ccm/api/1.0/pages/{cID} fails to enforce authorization checks on page-property, page-template, and page-type modifications. A user with only content-editing rights can bypass these checks via the REST API and set the header_extra_content attribute, which is rendered unescaped into the HTML head element. This allows persistent cross-site scripting (XSS) that affects all page visitors. The vulnerability requires HTTP network access to the API and a user account with content-editing permissions, but no additional user interaction is needed for the injected script to execute in visitors' browsers. A patch is available in Concrete CMS 9.5.3 and later.

Affected products

  • Concrete CMS Concrete CMS 9.2.0 through 9.5.2

Timeline

  • 2026-09-14: disclosed

References

Related threats