Access Control Flaw in Concrete CMS by Concrete Solutions
CVE-2026-18115
7.4HIGH
What is CVE-2026-18115?
Concrete CMS versions 9.2.0 through 9.5.2 are vulnerable to an access control issue within the REST API user endpoints. This vulnerability allows users with limited permissions to exploit the API and alter sensitive user information such as passwords, usernames, and email addresses. By possessing a specific update-scoped OAuth token, a user could potentially take over the accounts of non-superuser peers by changing their details, which poses a significant risk to the integrity of user accounts within Concrete CMS. Immediate action is recommended to secure your applications against this flaw.
Affected Version(s)
Concrete CMS 9.2.0 <= 9.5.2
