Authorization Bypass in Concrete CMS by Concrete5
CVE-2026-87028

5.3MEDIUM

Key Information:

Vendor
CVE Published:
16 September 2026

What is CVE-2026-87028?

Concrete CMS versions 9 to 9.5.3 display a critical flaw in the authorization process regarding board instances. An authenticated user with permission to edit contents on one board can exploit this vulnerability by submitting an identifier from a different board instance through the custom-slot preview endpoint. The system fails to verify that the requested InstanceItem belongs to the designated board for which the user has edit permissions and does not properly enforce page-view restrictions. Consequently, the user gains access to sensitive fields such as the page title and description of pages they are otherwise prohibited from viewing. This flaw raises significant security concerns for content management and user privacy.

Affected Version(s)

Concrete CMS 9.0.0 <= 9.5.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

polio123
.