CVE-2026-81910

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Configurations

Configuration 1 (hide)

cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*

History

16 Sep 2026, 17:40

Type Values Removed Values Added
References () https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes - () https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
First Time Concretecms concrete Cms
Concretecms

Information

Published : 2026-09-11 19:17

Updated : 2026-09-16 17:40


NVD link : CVE-2026-81910

Mitre link : CVE-2026-81910

CVE.ORG link : CVE-2026-81910


JSON object : View

Products Affected

concretecms

  • concrete_cms
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine