NONE · 0

CVE-2026-18423

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permissi...

Vulnerability Description

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore permanently delete, with no undo, or rename saved search presets owned by Express entities for which they had no permission, and a renamed preset name was displayed back to users of the targeted entity, enabling defacement or social engineering. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yalguun Tumenkhuu ( fg0x0 ) for reporting.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-18423?

CVE-2026-18423 is a documented vulnerability. Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permissi...

How severe is CVE-2026-18423?

CVSS scoring is not yet available for CVE-2026-18423. Check NVD for updates.

Is there a patch for CVE-2026-18423?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.