OAuth Authentication Bypass in Concrete CMS
CVE-2026-81906

6.3MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-81906?

Prior to version 9.5.3, Concrete CMS had a significant vulnerability where the OAuth callback login path did not validate whether an account was activated or the email was verified before allowing a session to be established. This issue enabled a deactivated or unvalidated user with an existing OAuth connection to successfully authenticate, resulting in an authenticated session being created. Login events were then recorded and dispatched, potentially leading to unauthorized access and security breaches.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tenzai
.