Access Control Flaw in Concrete CMS by Concrete Solutions
CVE-2026-18115

7.4HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-18115?

Concrete CMS versions 9.2.0 through 9.5.2 are vulnerable to an access control issue within the REST API user endpoints. This vulnerability allows users with limited permissions to exploit the API and alter sensitive user information such as passwords, usernames, and email addresses. By possessing a specific update-scoped OAuth token, a user could potentially take over the accounts of non-superuser peers by changing their details, which poses a significant risk to the integrity of user accounts within Concrete CMS. Immediate action is recommended to secure your applications against this flaw.

Affected Version(s)

Concrete CMS 9.2.0 <= 9.5.2

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.