CVE-2026-18422: Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization and CSRF Token Validation

Published Sep 15, 2026
·
Updated

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user who held the Edit Page Multilingual Settings permission on a single page could bind an arbitrary page in another locale as that source page's translation, and could delete legitimate translation pairs maintained by other editors, altering public-facing language routing across the site. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

Affected Software

1 affected component
Concrete CMS Concrete CMS<9.5.3

Event History

Sep 15, 2026
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation requires an authenticated user with the Edit Page Multilingual Settings permission on at least one page. The attacker does not need permission on the destination page in the other locale.

2

What can an attacker change?

They can assign an arbitrary page in another locale as a permitted source page's translation. They can also delete legitimate translation pairings maintained by other editors, which can alter public-facing language routing.

3

Are sites running the fixed release affected?

The issue affects Concrete CMS versions before 9.5.3. Version 9.5.3 is identified as the release containing the fix.

4

How can administrators assess possible impact?

Review multilingual translation assignments for unexpected pairings, missing legitimate translation pairs, and language-routing changes. Focus on pages where users had Edit Page Multilingual Settings permission but should not have been able to manage translations in other locales.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203