CVE-2026-81913
Last modified
CVE-2026-81913 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in the registration flow, giving a second entry point on sites with registration enabled. Concrete CMS versions prior to 9.5.0 do not include the rcURL parameter or this allowlist and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Michal M. for reporting.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Concrete CMS | Concrete CMS | >= 9.5.0, <= 9.5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-81913?
How severe is CVE-2026-81913?
How do I fix CVE-2026-81913?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81908Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization …6
- CVE-2026-81909Concrete CMS 9 through 9.5.2 is vulnerable to Missing Author…5.9
- CVE-2026-8191A vulnerability was identified in Wavlink NU516U1 M16U1_V240…8.8
- CVE-2026-81910Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Te…6.5
- CVE-2026-81911Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored…5.4
- CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Reques…5.7
- CVE-2026-81915Concrete CMS below 9.5.3 does not perform an object-level au…5.1
- CVE-2026-81916Concrete CMS before 9.5.3 evaluated the authorization check …4.3
- CVE-2026-81917Concrete CMS below 9.5.3 does not apply HTML output escaping…5.4
- CVE-2026-81918Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the…4.8
- CVE-2026-81919Concrete CMS below 9.5.3 did not validate an anti-CSRF token…4.3
- CVE-2026-8192A security flaw has been discovered in Wavlink NU516U1 M16U1…8.8
Are you affected by CVE-2026-81913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
