CVE-2026-81909 | Concrete CMS up to 9.5.2 Block Alias process.php Process::alias improper authorization

SecurityVulns

A vulnerability classified as problematic was found in Concrete CMS up to 9.5.2. The impacted element is the function Process::alias of the file concrete/controllers/backend/block/process.php of the component Block Alias. The manipulation results in improper authorization.

This vulnerability is identified as CVE-2026-81909. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More