Information Disclosure in Concrete CMS Leading to Unauthorized Data Access
CVE-2026-18120
6.3MEDIUM
What is CVE-2026-18120?
The legacy Express entry search endpoint in Concrete CMS versions prior to 9.5.3 is susceptible to information disclosure, allowing unauthenticated users to access sensitive entry search results. This issue arises due to a missing permission check on the endpoint, exposing attribute values that should only be available to privileged users. Particularly, in scenarios where Express entities do not implement entry-specific permissions, the security measures are further weakened, creating potential risks for unauthorized data access. It is essential for users to update to version 9.5.3 or later to safeguard against this vulnerability.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
