REST API User Creation Vulnerability in Concrete CMS by Concrete5
CVE-2026-87031
2.1LOW
What is CVE-2026-87031?
In versions 9.2.0 through 9.5.3 of Concrete CMS, a vulnerability exists within the REST API's user creation endpoint that fails to enforce proper permission checks. This oversight allows any valid OAuth token, even those without user context, to create new user accounts without the need for email verification or administrator approval. Consequently, newly created accounts can gain access to editing page content under default settings, which poses a significant risk for stored cross-site scripting attacks and potential further exploitation of the system.
Affected Version(s)
Concrete CMS 9.2.0 <= 9.5.3
