Junglewise Threat Intelligence

CVE-2026-81916: Concrete CMS authorization bypass in Express entry submission

CVE-2026-81916 · Severity: medium · CVSS 4.3 · Published 2026-09-11

Technologies: Concrete CMS. Vendors: Concrete CMS.

Executive brief

Concrete CMS is an open-source content management system used to build and manage websites. A vulnerability in Express entry submission allows an authenticated user with permission to add entries to one data collection to instead create entries in other collections they do not have authorization for. An attacker could exploit this to inject unauthorized content, corrupt data, or trigger unintended workflows.

Technical details

The vulnerability is an authorization bypass in the Express entry submission handler. The dashboard submit route resolves the target entity from the attacker-controlled route ID parameter, but the permission check validates against the independently posted form's entity. These two entities are never compared, allowing an attacker with high-privilege access to one Express object to submit entries to a different object by manipulating the route ID. The flaw requires high-level user privileges (PR:H) to exploit but enables lateral privilege escalation and data integrity violations across Express objects.

Affected products

  • Concrete CMS Concrete CMS before 9.5.3

Timeline

  • 2026-09-11: disclosed

References

Related threats