# CVE-2026-81902

## Summary

- **CVE ID:** CVE-2026-81902
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-352
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 15, 2026

## Description

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on the target page, deleted every block on that page's current version; blocks not aliased to another page or scrapbook entry were also removed from the global Blocks table and their block-type data table, permanently destroying the content. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.

## Affected Products

- Concrete CMS — Concrete CMS (9.0.0)

## References

- [CNA](https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 8.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._