Authorization Bypass in Concrete CMS by Concrete5
CVE-2026-87028
What is CVE-2026-87028?
Concrete CMS versions 9 to 9.5.3 display a critical flaw in the authorization process regarding board instances. An authenticated user with permission to edit contents on one board can exploit this vulnerability by submitting an identifier from a different board instance through the custom-slot preview endpoint. The system fails to verify that the requested InstanceItem belongs to the designated board for which the user has edit permissions and does not properly enforce page-view restrictions. Consequently, the user gains access to sensitive fields such as the page title and description of pages they are otherwise prohibited from viewing. This flaw raises significant security concerns for content management and user privacy.
Affected Version(s)
Concrete CMS 9.0.0 <= 9.5.3
