Predictable Digital Download Tokens in Concrete CMS Community Store
CVE-2026-95653

8.7HIGH

Key Information:

Vendor
CVE Published:
22 September 2026

What is CVE-2026-95653?

The Community Store prior to version 2.7.8 has a security flaw that exposes digital product download tokens to unauthorized access. The system derives these tokens from order creation timestamps rather than employing secure random values. This predictability allows unauthenticated attackers to enumerate sequential order and file identifiers, enabling them to calculate valid download tokens. Consequently, attackers can retrieve digital goods purchased by other customers, leading to potential data breaches and loss of trust. It is imperative for users to upgrade to version 2.7.8 or later to mitigate this vulnerability.

Affected Version(s)

community_store 0 < 2.7.8

community_store 2.7.8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Prince Edem Fiagbedzi
.