Predictable Digital Download Tokens in Concrete CMS Community Store
CVE-2026-95653
8.7HIGH
What is CVE-2026-95653?
The Community Store prior to version 2.7.8 has a security flaw that exposes digital product download tokens to unauthorized access. The system derives these tokens from order creation timestamps rather than employing secure random values. This predictability allows unauthenticated attackers to enumerate sequential order and file identifiers, enabling them to calculate valid download tokens. Consequently, attackers can retrieve digital goods purchased by other customers, leading to potential data breaches and loss of trust. It is imperative for users to upgrade to version 2.7.8 or later to mitigate this vulnerability.
Affected Version(s)
community_store 0 < 2.7.8
community_store 2.7.8
