# CVE-2026-81915

## Summary

- **CVE ID:** CVE-2026-81915
- **Severity:** MEDIUM
- **CVSS Score:** 5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-862, CWE-639
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 11, 2026

## Description

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditPageType(), so a signed-in dashboard user permitted to edit one Page Type could modify the configuration of Page Types outside their assigned authorization boundary. The update_page_type token was validated but is action- and user-scoped rather than object-scoped, so it did not constrain which Page Type could be targeted. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Andrew Gonzalez for reporting.

## Affected Products

- Concrete CMS — Concrete CMS (5.0.0)

## References

- [CNA](https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._