REST API User Creation Vulnerability in Concrete CMS by Concrete5
CVE-2026-87031

2.1LOW

Key Information:

Vendor
CVE Published:
16 September 2026

What is CVE-2026-87031?

In versions 9.2.0 through 9.5.3 of Concrete CMS, a vulnerability exists within the REST API's user creation endpoint that fails to enforce proper permission checks. This oversight allows any valid OAuth token, even those without user context, to create new user accounts without the need for email verification or administrator approval. Consequently, newly created accounts can gain access to editing page content under default settings, which poses a significant risk for stored cross-site scripting attacks and potential further exploitation of the system.

Affected Version(s)

Concrete CMS 9.2.0 <= 9.5.3

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

winstoncrooker
.