Information Disclosure in Concrete CMS Leading to Unauthorized Data Access
CVE-2026-18120

6.3MEDIUM

Key Information:

Vendor
CVE Published:
16 September 2026

What is CVE-2026-18120?

The legacy Express entry search endpoint in Concrete CMS versions prior to 9.5.3 is susceptible to information disclosure, allowing unauthenticated users to access sensitive entry search results. This issue arises due to a missing permission check on the endpoint, exposing attribute values that should only be available to privileged users. Particularly, in scenarios where Express entities do not implement entry-specific permissions, the security measures are further weakened, creating potential risks for unauthorized data access. It is essential for users to update to version 9.5.3 or later to safeguard against this vulnerability.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

man-like-dan
.