CVE-2026-81913
Dashboard / Vulnerabilities / CVE-2026-81913
CVE-2026-81913
Summary: Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter.
Details: Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in the registration flow, giving a second entry point on sites with registration enabled. Concrete CMS versions prior to 9.5.0 do not include the rcURL parameter or this allowlist and are not affected. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Michal M. for reporting.
References: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81913.json, https://github.com/concretecms/concretecms, https://nvd.nist.gov/vuln/detail/CVE-2026-81913
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
