CVE-2026-18421: Concrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authorization check, allowing a low-privileged board editor to modify or delete configured data sources on boards they do not control

Published Sep 15, 2026
·
Updated

Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, updatedatasource, and deletedatasource), which resolve a ConfiguredDataSource directly from an attacker-supplied identifier without confirming the requester's edit permission on the owning board. A user granted editboardsettings on a single board was therefore able to modify or permanently delete the configured data sources of any other board on the site, halting the affected board's content feed and resetting its custom weighting. The CSRF token that guards these actions was validated but bound to the action name rather than to the target object, so a token legitimately obtained for one board could be replayed against another board's ConfiguredDataSource identifier and did not constrain access. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

Affected Software

1 affected component
Concrete CMS Boards data source dashboard>=9.0.0<=9.5.2

Event History

Sep 15, 2026
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionWeakness

Frequently Asked Questions

1

What level of access does an attacker need?

The attacker must be an authenticated user with edit_board_settings permission on at least one board. They can then target configured data sources belonging to other boards without having edit permission for those boards.

2

Does the CSRF token prevent cross-board abuse?

No. Although the affected actions validate a CSRF token, the token is bound only to the action name and not to the target configured data source or its owning board, allowing a token obtained for one board to be replayed against another board's identifier.

3

What is the practical impact on a targeted board?

An attacker can modify or permanently delete its configured data sources. This can halt the board's content feed and reset its custom weighting.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203