Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81906— [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 9.5.3 版本之前,Concrete CMS 的 OAuth 回调登录路径在建立会话时,未检查账户是否处于激活状态或邮箱是否已验证。一个已停用或未经邮箱验证但已绑定 OAuth 的用户,可以完成身份验证并获得一个针对回调响应完全认证的会话,同时登录会被记录,且登录事件也会被触发。 Concrete CMS 安全团队为此漏洞赋予了 CVSS v4.0 评分 6.3,其向量为:CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N。感谢 Te

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1083 · File and Directory Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81906

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用候选路径或通道进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 5.0.0 ~ 9.5.2 -

II. Public POCs for CVE-2026-81906

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81906

登录查看更多情报信息。

Vendor Pages for CVE-2026-81906 (1)

Same Patch Batch · Concrete CMS · 2026-09-10 · 5 CVEs total

CVE-2026-81905 6.3 MEDIUM Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a h
CVE-2026-18121 6.3 MEDIUM Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calend
CVE-2026-68527 5.9 MEDIUM Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-con
CVE-2026-84432 5.3 MEDIUM Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog contro

IV. Related Vulnerabilities

V. Comments for CVE-2026-81906

No comments yet


Leave a comment