OAuth Authentication Bypass in Concrete CMS
CVE-2026-81906
6.3MEDIUM
What is CVE-2026-81906?
Prior to version 9.5.3, Concrete CMS had a significant vulnerability where the OAuth callback login path did not validate whether an account was activated or the email was verified before allowing a session to be established. This issue enabled a deactivated or unvalidated user with an existing OAuth connection to successfully authenticate, resulting in an authenticated session being created. Login events were then recorded and dispatched, potentially leading to unauthorized access and security breaches.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
