CVE-2026-18425
Last modified
CVE-2026-18425 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each page's display order. As a result, an authenticated user granted sitemap access could change the display order (cDisplayOrder) of any pages they had no rights to edit, altering the order in which those pages render in navigation, breadcrumb, and page-list output. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before updating each page's display order. As a result, an authenticated user granted sitemap access could change the display order (cDisplayOrder) of any pages they had no rights to edit, altering the order in which those pages render in navigation, breadcrumb, and page-list output. The reorder action additionally validated no CSRF token, so the write could be triggered by a forged request. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | >= 9.0.0, < 9.5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-18425?
How severe is CVE-2026-18425?
How do I fix CVE-2026-18425?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1842HyperCloud versions 2.3.5 through 2.6.8 improperly allowed r…6.2
- CVE-2026-18420Improper input validation in the Time Series Visual Builder …8.8
- CVE-2026-18421Concrete CMS 9 through 9.5.2 does not perform an authorizati…2.1
- CVE-2026-18422Concrete CMS before 9.5.3 did not enforce a destination-side…6.5
- CVE-2026-18423Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure d…7.1
- CVE-2026-18424Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Req…7.1
- CVE-2026-18426Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-lev…6.5
- CVE-2026-18427@fastify/static before version 10.1.3 contains an incomplete…7.5
- CVE-2026-18428A SQL query validation bypass in the Flint extension query h…8.8
- CVE-2026-1843The Super Page Cache plugin for WordPress is vulnerable to S…7.2
- CVE-2026-18430HumHub 1.18.4 contains a stored cross-site scripting vulnera…7.2
- CVE-2026-18431The Avada theme for WordPress is vulnerable to Arbitrary Fil…9.8
Are you affected by CVE-2026-18425?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
