Authorization Bypass in Concrete CMS Blocks by Concrete CMS
CVE-2026-68535

5.1MEDIUM

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-68535?

The block-create endpoint in Concrete CMS versions 9.2.0 to 9.5.2 lacks a validation mechanism for submitted data, particularly for file-referencing blocks like hero_image and gallery. This oversight allows authenticated users with block-add permissions to improperly store references to files that should otherwise be restricted based on the user's file-manager visibility. Consequently, this vulnerability can lead to unauthorized exposure of file URLs and thumbnails to both editors and public visitors of the affected pages. The Concrete CMS security team has acknowledged this issue, emphasizing the need for rigorous file management and validation processes.

Affected Version(s)

Concrete CMS 9.2.0 <= 9.5.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.