Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81905— Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 9.5.3 以下版本将用户验证哈希值(用于多种用途,包括邮箱/注册验证、密码重置和持久化登录)统一存储在一个带“类型”列的单表中。然而,哈希值核销(redemption)路径仅根据哈希值本身进行解析,并未校验其对应的用途类型。因此,原本用于某一用途的哈希值可能被用于另一用途:例如,一个长期有效的注册哈希值(有效期 60 天)可被提交到密码修改接口,从而为目标账户设置新密码;而一个密码重置哈希值也可被提交到邮箱验证接口以激活账户。 利用该漏洞的前提是攻击者需通过其他渠道先获取一个有效的哈希值

CVSS 6.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81905

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a result, a hash issued for one purpose can be redeemed for another: a long-lived registration hash (60-day expiry) can be submitted to the password-change endpoint to set a new password on the target account, and a password-reset hash can be submitted to the email-validation endpoint to activate an account. Exploitation requires the attacker to first obtain a valid hash through a separate channel (for example email interception, log exposure, or SSRF against an internal mail relay), so the flaw amplifies the impact of any hash disclosure rather than creating a standalone entry point. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 5.0.0 ~ 9.5.2 -

II. Public POCs for CVE-2026-81905

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81905

登录查看更多情报信息。

Vendor Pages for CVE-2026-81905 (1)

Same Patch Batch · Concrete CMS · 2026-09-10 · 5 CVEs total

CVE-2026-81906 6.3 MEDIUM [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
CVE-2026-18121 6.3 MEDIUM Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calend
CVE-2026-68527 5.9 MEDIUM Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-con
CVE-2026-84432 5.3 MEDIUM Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog contro

IV. Related Vulnerabilities

V. Comments for CVE-2026-81905

No comments yet


Leave a comment