Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
References
| Link | Resource |
|---|---|
| https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes | Broken Link |
Configurations
History
16 Sep 2026, 17:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes - Broken Link | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | |
| First Time |
Concretecms concrete Cms
Concretecms |
Information
Published : 2026-09-11 19:17
Updated : 2026-09-16 17:40
NVD link : CVE-2026-81910
Mitre link : CVE-2026-81910
CVE.ORG link : CVE-2026-81910
JSON object : View
Products Affected
concretecms
- concrete_cms
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
