Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81909— Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 9 至 9.5.2 版本存在缺失授权(Missing Authorization)漏洞,位于区块别名路由( ,位于 )中。 该路由未能验证所引用的区块在目标页面上是否确为“孤立”状态,也未能验证调用者是否对源区块拥有任何权限。因此,一个仅被授予自己页面上“向指定区域添加区块”(area-scoped add_block_to_area)委托权限的用户,可以传入站点内任意区块 ID。结果,源区块的内容会被复制到一个由该非授权编辑者可控制的区域中,从而泄露该内容;同时,原始区块会在同一请求中被

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81909

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any permission over the source block. A user granted only an area-scoped add_block_to_area delegation on their own page can therefore pass any block ID on the site: the source block's content is duplicated into an area the rogue editor controls, disclosing that content, and the original block is then force-deleted in the same request, destroying arbitrary site content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 9.0.0 ~ 9.5.2 -

II. Public POCs for CVE-2026-81909

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81909

登录查看更多情报信息。

Vendor Pages for CVE-2026-81909 (1)

Same Patch Batch · Concrete CMS · 2026-09-11 · 5 CVEs total

CVE-2026-81908 6.0 MEDIUM Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows
CVE-2026-18122 6.0 MEDIUM Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr
CVE-2026-68528 6.0 MEDIUM Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca
CVE-2026-81910 5.9 MEDIUM Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The

IV. Related Vulnerabilities

V. Comments for CVE-2026-81909

No comments yet


Leave a comment