目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-68535— Concrete CMS 9.5.2 远程代码执行漏洞

一分钟漏洞结论

影响对象
Concrete CMS Concrete CMS
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Concrete CMS 区域 API(Area API)的 block-create 端点在 9.2.0 至 9.5.2 版本中,未对提交的数据调用区块类型控制器的 方法。对于涉及文件引用的区块(如 和 ),该 方法正是用于将所引用的文件与用户的文件管理器可见性策略进行授权校验的地方。 由于这一缺失,拥有 block-add 权限范围的已认证用户可以保存并导致页面渲染出指向某个文件的引用,而该文件本应被文件管理器授权策略拒绝。这会导致该文件的 URL 及其预览图向编辑者以及访问受影响页面的访客披露。 在公共文件存

CVSS 5.1 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-68535 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions
来源: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the referenced file is authorized against the user's file-manager visibility. As a result, an authenticated user holding the block-add scope could store, and cause the page to render, a reference to a file that the file-manager authorization policy would otherwise reject, disclosing that file's URL and preview to the editor and to visitors of the affected page. Under public file storage, the URL and thumbnail are exposed directly; under private storage, the disclosure is limited by the permission-checked download URL. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Concrete CMS Concrete CMS 9.2.0 ~ 9.5.2 -

二、漏洞 CVE-2026-68535 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-68535 的情报信息

登录查看更多情报信息。

CVE-2026-68535 厂商页面 (1)

同批安全公告 · Concrete CMS · 2026-09-11 · 共 15 条

CVE-2026-81907 6.1 MEDIUM Concrete CMS 9.5.2 CSRF批量删除漏洞
CVE-2026-81908 6.0 MEDIUM Concrete CMS 9.2.0 至 9.5.2 组枚举漏洞
CVE-2026-18122 6.0 MEDIUM Concrete CMS 9.2.0-9.5.2 未授权访问漏洞
CVE-2026-68528 6.0 MEDIUM Concrete CMS 9.5.2 存储型XSS漏洞
CVE-2026-81909 5.9 MEDIUM Concrete CMS 9.5.2 缺失授权致数据泄露
CVE-2026-81910 5.9 MEDIUM Concrete CMS 9至9.5.2 服务端模板注入漏洞
CVE-2026-81911 5.8 MEDIUM Concrete CMS 9.0.0-9.5.2 存储型XSS漏洞
CVE-2026-81912 5.7 MEDIUM Concrete CMS 9.5.3之前版本 跨站请求伪造漏洞
CVE-2026-81913 5.3 MEDIUM Concrete CMS 9.5.0-9.5.2 URL开放重定向漏洞
CVE-2026-68526 5.3 MEDIUM Concrete CMS 9.5.3前 日历事件重复控制器CSRF漏洞
CVE-2026-81915 5.1 MEDIUM Concrete CMS 9.5.3 权限验证漏洞
CVE-2026-81917 5.1 MEDIUM Concrete CMS 9.5.3 以下 存储型XSS漏洞
CVE-2026-81916 5.1 MEDIUM Concrete CMS 9.5.3 以下版本越权创建条目漏洞
CVE-2026-81918 4.8 MEDIUM Concrete CMS 9.5.3以下存储型XSS漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-68535

暂无评论


发表评论