Authorization Bypass in Concrete CMS Blocks by Concrete CMS
CVE-2026-68535
5.1MEDIUM
What is CVE-2026-68535?
The block-create endpoint in Concrete CMS versions 9.2.0 to 9.5.2 lacks a validation mechanism for submitted data, particularly for file-referencing blocks like hero_image and gallery. This oversight allows authenticated users with block-add permissions to improperly store references to files that should otherwise be restricted based on the user's file-manager visibility. Consequently, this vulnerability can lead to unauthorized exposure of file URLs and thumbnails to both editors and public visitors of the affected pages. The Concrete CMS security team has acknowledged this issue, emphasizing the need for rigorous file management and validation processes.
Affected Version(s)
Concrete CMS 9.2.0 <= 9.5.2
