Authorization Code Handler Vulnerability in Concrete CMS by Concrete5
CVE-2026-7887
2.3LOW
What is CVE-2026-7887?
In versions of Concrete CMS prior to 9.5.0, an exploitable flaw in the OAuth 2.0 authorization-code handler allows users with suspended or inactive accounts to authenticate successfully. This issue permits unauthorized access to valid API tokens, posing a significant security risk. Users who should be restricted still gain access, creating potential for misuse and data exposure. The issue was reported by security researcher 0x4c616e and documented in recent release notes.
Affected Version(s)
Concrete CMS 5.0 <= 9.5.0
