MEDIUMVulnerability

CVE-2026-81916

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to one Express object could create entries in a different Express object outside their authorization scope, potentially polluting protected datasets, triggering workflows, or injecting content into administrative processes. The dashboard submit route resolved the mutated entity from the attacker-controlled route ID while the permission check validated the independently posted form's entity, and the submission proceeded because the two entities were never compared. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-81916
signal_observed_at
2026-09-21T23:07:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
published_at
2026-09-11T20:19:14.433
last_modified
2026-09-18T15:23:18.233

Related Entities (4)

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (2)

[Weakness]Authorization Bypass Through User-Controlled Key
[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81916 — Ninja Signal Threat Intelligence | Ninja Signal