Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18115— In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover.

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 版本 9.2.0 至 9.5.2 未在 REST API 的用户写入端点(即 和 )上强制实施针对每个字段的 权限控制。因此,一个持有更新范围(update-scoped)OAuth 令牌且仅被授权编辑单个非敏感字段的用户,能够修改另一位非超级用户的密码、用户名、邮箱和属性,从而接管该账户。 Concrete CMS 安全团队将该漏洞的 CVSS v4.0 评分定为 7.4,向量值为: 感谢 riodrwn 报告此漏洞。

CVSS 7.4 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
Concrete CMS Concrete CMS 9.2.0≤ 9.5.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18115

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover.
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password). A user with an update-scoped OAuth token and permission to edit only one non-sensitive field could change another non-superuser's password, username, email, and attributes, taking over that account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.4 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 9.2.0 ~ 9.5.2 -

II. Public POCs for CVE-2026-18115

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18115

登录查看更多情报信息。

Vendor Pages for CVE-2026-18115 (1)

Same Patch Batch · Concrete CMS · 2026-09-15 · 27 CVEs total

CVE-2026-18110 8.7 HIGH Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user select
CVE-2026-81894 8.5 HIGH Concrete CMS 9.5.2 and below is vulnerable to Stored DOM-based Cross-site Scripting (XSS)
CVE-2026-18111 8.5 HIGH Concrete CMS below 9.5.4 allows privilege escalation because adding users and assigning gr
CVE-2026-81895 8.5 HIGH Concrete CMS 9.5.2 and below is vulnerable to Stored SQL Injection in Concrete CMS Documen
CVE-2026-81896 8.4 HIGH Concrete CMS below version 9.5.3 is vulnerable to Stored XSS in Concrete CMS Form Submissi
CVE-2026-81897 7.7 HIGH Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via Express form Text control
CVE-2026-81898 7.5 HIGH Concrete CMS below version 9.5.3 is vulnerable to Stored XSS via country-less Address att
CVE-2026-18113 7.5 HIGH Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS in the Top Navigation Bar Block via
CVE-2026-81899 7.3 HIGH Concrete CMS 9.0 to 9.5.2 is vulnerable to Stored XSS via group folder name on the Members
CVE-2026-81920 2.3 LOW Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Dashboard S
CVE-2026-81921 2.3 LOW In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Account Status
CVE-2026-68532 2.3 LOW Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type Deletion Dashb
CVE-2026-68534 2.3 LOW Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in
CVE-2026-68533 2.3 LOW Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows
CVE-2026-81919 2.3 LOW Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Block Arran
CVE-2026-81922 2.1 LOW "In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap page reorder a
CVE-2026-81924 2.1 LOW Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in Theme Page
CVE-2026-81923 2.1 LOW Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta Tags editor
CVE-2026-18421 2.1 LOW Concrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authorization check, a
CVE-2026-68530 2.1 LOW Concrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance Actions Allowe

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-18115

No comments yet


Leave a comment