Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Authorization in Stack/Container Sub-Block Asset Registration | Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registration |
Tue, 08 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's asset registration — such as a site's configured Google Maps API key — from any public page embedding an affected Stack, Container, or layout area, despite the block-level permission restriction. Any sub-block type whose asset or header hooks output configuration values is affected. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting. | |
| Title | Missing Authorization in Stack/Container Sub-Block Asset Registration | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ConcreteCMS
Published:
Updated: 2026-09-08T23:37:04.415Z
Reserved: 2026-08-27T18:21:25.200Z
Link: CVE-2026-81904
No data.
Status : Received
Published: 2026-09-08T22:19:16.107
Modified: 2026-09-08T22:19:16.107
Link: CVE-2026-81904
No data.
OpenCVE Enrichment
No data.