Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18122— Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 9.2.0 至 9.5.2 版本中,Express REST API 的列表端点因缺少授权检查,导致受限的 Express 条目暴露出来。具体而言,Concrete CMS 的 REST API 中 Express 条目集合端点禁用了针对单个条目的查看权限检查。因此,仅具有 Express 实体读取范围的 OAuth 令牌,能够枚举其用户上下文本无权查看的条目,从而泄露每条条目的公开标识符、URL、标签、日期,以及通过 参数请求的任意属性或关联条目数据。 Concrete CMS 安全团队

CVSS 6.0 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18122

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express entity could enumerate entries that its user context lacked permission to view, disclosing each entry's public identifier, URL, label, dates, and any attribute or associated-entry data requested via the includes parameter. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 9.2.0 ~ 9.5.2 -

II. Public POCs for CVE-2026-18122

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18122

登录查看更多情报信息。

Vendor Pages for CVE-2026-18122 (1)

Same Patch Batch · Concrete CMS · 2026-09-11 · 5 CVEs total

CVE-2026-81908 6.0 MEDIUM Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows
CVE-2026-68528 6.0 MEDIUM Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca
CVE-2026-81909 5.9 MEDIUM Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block
CVE-2026-81910 5.9 MEDIUM Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The

IV. Related Vulnerabilities

V. Comments for CVE-2026-18122

No comments yet


Leave a comment