Missing Authorization in Concrete CMS Express REST API Affects User Data Access
CVE-2026-18122

6MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-18122?

The Concrete CMS Express REST API has a critical flaw that allows authenticated users to access restricted data without proper authorization checks. Specifically, the API's endpoint for listing Express entries fails to enforce per-entry view permissions, which can lead to unauthorized disclosures of sensitive information. An attacker can use an OAuth token with read permissions to enumerate entries that the user should not have access to, revealing identifiers, URLs, labels, and various attributes of the Express entries. This vulnerability poses a significant risk to user privacy and data security within the Concrete CMS environment.

Affected Version(s)

Concrete CMS 9.2.0 <= 9.5.2

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.