Concrete CMS 9.2.0 至 9.5.2 版本的 REST API “组(Groups)列表”接口存在授权缺失漏洞。位于 中的 方法注册了一个权限检查器回调,该回调无条件返回 ,导致在返回组集合时,并未对每个对象(树节点)执行具体的授权检查。 这意味着,只要某个已认证用户的 API token 包含 作用域,该用户即可调用 ,从而获取站点上的所有组信息,无视这些组上的查看权限限制。此漏洞会泄露组织的组结构、角色以及访问层级信息。 Concrete CMS 安全团队为该漏洞分配的 CVSS v4.0 评分
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 9.2.0 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18122 | 6.0 MEDIUM | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entr |
| CVE-2026-68528 | 6.0 MEDIUM | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unesca |
| CVE-2026-81909 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block |
| CVE-2026-81910 | 5.9 MEDIUM | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in The |
No comments yet