CVE-2026-68530: Concrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance Actions Allowed a Board Editor to Access and Delete Other Boards' Instances

Published Sep 15, 2026
·
Updated

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-supplied instance ID and then viewed, refreshed, regenerated, or deleted it without verifying that the requester held editboardsettings on the instance's parent board. As a result, a user granted board-edit rights on a single board could reach the instances of any other board on the site by supplying their instance IDs. The affected actions bypassed the controller's permission-checked accessor (the same accessor used by the read view, which runs canEditBoardSettings on the parent board) and validated only an action-scoped CSRF token, which is bound to the action name rather than to the target object and is therefore reusable across boards. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

Affected Software

1 affected component
Concrete CMS Concrete CMS>=9.0.0<=9.5.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure every board-instance action in the Dashboard Boards area (view, refresh, regenerate, delete) verifies that the requester holds edit_board_settings on the instance's parent board before resolving the instance ID and performing the action.

    Concrete CMS Boards area (instance details controller) Authorization check for board-instance actions = required

Event History

Sep 15, 2026
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
DescriptionWeakness

Frequently Asked Questions

1

Which users could exploit this issue?

An authenticated user with board-edit rights on at least one board could access board instances belonging to other boards. The CVSS vector identifies the required privileges as high.

2

What does an attacker need to do to access another board's instances?

They need to supply the target board instance's ID to the affected Dashboard instance actions and provide a valid action-scoped CSRF token. The token is reusable across boards because it is tied to the action name rather than the targeted board instance.

3

Which operations could be performed against another board's instances?

The affected actions could view, refresh, regenerate, or delete a board instance. The impact is limited to integrity and availability in the provided CVSS vector, with no confidentiality impact listed.

4

How can I determine whether my deployment is affected?

Deployments running Concrete CMS versions 9.0.0 through 9.5.2 are affected. Review which users have board-edit rights, since those users could potentially target instances associated with other boards.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203