NONE · 0

CVE-2026-81926

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted...

Vulnerability Description

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-side JavaScript inserted each value into the dialog as raw HTML, so a crafted page path executed script in the editor's authenticated browser session. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-81926?

CVE-2026-81926 is a documented vulnerability. Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted...

How severe is CVE-2026-81926?

CVSS scoring is not yet available for CVE-2026-81926. Check NVD for updates.

Is there a patch for CVE-2026-81926?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.