CVE-2026-81923: Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editor

Published Sep 15, 2026
·
Updated

In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the per-page CSRF token but never called canEditPageProperties() for the target page, so a user who was granted access to the bulk SEO tool and could view (but not edit) a given page was able to change that page's meta title, meta description, and URL handle outside their edit scope, tampering with the presentation and live URLs of otherwise protected content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.

Affected Software

1 affected component
Concrete CMS Concrete CMS<9.5.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Concrete CMS to a version that resolves this vulnerability.

    Fixed in 9.5.3
  2. Configuration

    Update the SEO Bulk Update Meta Tags editor saveRecord() logic to call canEditPageProperties() for the target page so only users with per-page edit permissions can modify meta title, meta description, and URL handle.

    Concrete CMS SEO Bulk Update Meta Tags editor Authorization check before saving (per-page permissions) = Ensure canEditPageProperties() is called for the target page before saving changes

Event History

Sep 15, 2026
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user must be granted access to the SEO Bulk Update Meta Tags tool and be able to view the target page. They do not need permission to edit that page's properties.

2

What changes could an unauthorized user make?

They could change the target page's meta title, meta description, and URL handle. This can alter the page's presentation and its live URL despite the user lacking page-edit permission.

3

Are installations affected by default?

Exploitation depends on granting a user access to the bulk SEO tool while that user can view pages they are not allowed to edit. The provided information does not establish whether that permission arrangement exists by default.

4

What version resolves the issue?

Concrete CMS 9.5.3 resolves the missing per-page authorization check. Versions before 9.5.3 are affected.

5

What can be done before updating?

Restrict access to the SEO Bulk Update Meta Tags tool to users who are authorized to edit every page they can view through it. Review changes to meta titles, descriptions, and URL handles for protected pages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203